Agent skill

Selective Instrument

by opensage-agent in opensage-agent/opensage-adk

Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk.

Apache-2.0Auto-check passedSecurity

Install Selective Instrument

skills CLI
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .claude/skills/selective-instrument && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
selective-instrument
GitHub stars
127
Token cost
~1.1k tokens
SKILL.md length
363 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk.

  • Works in 3 steps: Quickly discover inputs that reach the… → Collect characteristic seeds — inputs… → Feed those seeds into a conventional…
  • Tasks that involve Fuzzing
  • SKILL.md covers Purpose, Workflow, Tools and Requires Sandbox, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Selective Instrument is an agent skill from opensage-agent/opensage-adk. Selective AFL++ instrumentation for directed fuzzing. Agent writes target functions/files to /fuzz/allowlist.txt, recompiles with AFLLLVMALLOWLIST, then runs directed fuzzing to quickly reach the target region and collect characteristic seeds for further analysis or conventional fuzzing.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Fuzzing

Example prompts

  • “/selective-instrument”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Quickly discover inputs that reach the target region (e.g., a patched
  2. Collect characteristic seeds — inputs that exercise the target code
  3. Feed those seeds into a conventional full-instrumented fuzzer for deeper

What it can do on your machine

Read from SKILL.md and the folder at commit 54d6470. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Selective Instrument loads about 1.1k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 363 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from opensage-agent/opensage-adk at commit 54d6470, republished under its Apache-2.0 licence (© opensage-agent). 363 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/selective-instrument/SKILL.md (or your agent's skills folder).
name
selective-instrument
description
Selective AFL++ instrumentation for directed fuzzing. Agent writes target functions/files to /fuzz/allowlist.txt, recompiles with AFL_LLVM_ALLOWLIST, then runs directed fuzzing to quickly reach the target region and collect characteristic seeds for further analysis or conventional fuzzing.
should_run_in_sandbox
fuzz
returns_json
false

Selective Instrument

Directed fuzzing via AFL++ selective instrumentation. Only the specified functions or source files are instrumented, so AFL++ coverage feedback is limited to the target region. This makes the fuzzer converge quickly toward inputs that exercise those specific code paths.

Purpose

Selective instrumentation is a directed fuzzing technique:

  1. Quickly discover inputs that reach the target region (e.g., a patched function, a suspected vulnerability)
  2. Collect characteristic seeds — inputs that exercise the target code
  3. Feed those seeds into a conventional full-instrumented fuzzer for deeper mutation-based exploration, or use them for further analysis (coverage, debugging, PoC generation)

The instrumented binary is written to /out_selective (not /out), so the original full-instrumented build is preserved.

Workflow

  1. Identify targets: Use static analysis, patch diff, or code review to determine which functions or files to focus on.

  2. Write the allowlist: Create /fuzz/allowlist.txt in the fuzz sandbox with one entry per line. Use run_terminal_command to write it:

    cat > /fuzz/allowlist.txt << 'EOF'
    fun:parse_header
    fun:decode_payload
    src:lib/parser.c
    EOF

    Allowlist syntax (AFL_LLVM_ALLOWLIST format):

    • fun:<name> — instrument a specific function (wildcards OK: fun:parse_*)
    • src:<path> — instrument all functions in a source file
    • mod:<path> — instrument all functions in files under a directory
  3. Recompile with selective instrumentation:

    bash
    /bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh

    (Optional extra entries can be passed as arguments — they are appended to the existing allowlist file.)

  4. Run directed fuzzing to collect seeds that reach the target:

    bash
    /bash_tools/fuzz/selective-instrument/scripts/run_selective_fuzz.sh <fuzz_target> <duration_seconds> [seed_paths...] [--custom_mutator_path <path>] [--reset_output]
  5. Use the collected seeds: The fuzzing output (including seeds and crashes) is in /fuzz/out_selective/. Feed interesting seeds into the full-instrumented run-fuzzing-campaign, or use them for coverage analysis, debugging, or PoC generation.

Show full SKILL.md (115 more words)Show less

Tools

selective_instrument.sh — Recompile with allowlist

Reads /fuzz/allowlist.txt (which the agent must create beforehand), optionally appends extra entries from arguments, then recompiles the project with AFL_LLVM_ALLOWLIST into /out_selective.

bash
# Typical: agent already wrote /fuzz/allowlist.txt
/bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh

# Or append extra entries via arguments
/bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh "fun:extra_func"
run_selective_fuzz.sh — Directed fuzzing

Runs AFL++ using the selectively instrumented binary from /out_selective. Output goes to /fuzz/out_selective/.

bash
/bash_tools/fuzz/selective-instrument/scripts/run_selective_fuzz.sh <fuzz_target> <duration_seconds> [seed_paths...] [--custom_mutator_path <path>] [--reset_output]
Parameters
fuzz_target (required, positional position 0)

Type: str

Fuzz target binary name (looked up in /out_selective/<fuzz_target>).

duration_seconds (required, positional position 1)

Type: int

Fuzzing duration in seconds.

seed_paths (optional, positional position 2+)

Type: list of strings

Optional seed file/dir paths.

--custom_mutator_path (optional, named parameter)

Type: str

Optional path to a custom mutator python script.

--reset_output (optional, flag)

Type: bool (default: false)

Reset output and start fresh.

Requires Sandbox

fuzz

Timeout

3600 seconds

© opensage-agent, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/opensage/bash_tools/fuzz/selective-instrument of opensage-agent/opensage-adk.

Open the folder on GitHubat commit 54d6470

Compare with similar skills

Selective Instrument next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Selective Instrument compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Selective Instrument this skillopensage-agent/opensage-adk127—~1.1kAutomated safety check: PassApache-2.0
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Fizz Syncpashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT
Research FuzzerARA-Labs/Agent-Native-Research-Artifact692—~2.4kAutomated safety check: PassMIT
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone
Binary Reverse Engineering Audittihanyin/REx-skill107—~5.1kAutomated safety check: PassMIT

Similar skills

  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Research Fuzzer

    ARA-Labs/Agent-Native-Research-Artifact

    Treat an open-ended investigation the way a fuzzer treats a program.

    692 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

    107 GitHub stars~5.1k tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed

More from opensage-agent/opensage-adk

All 21 skills in this repo
  • Run Fuzzing Campaign

    opensage-agent/opensage-adk

    Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

    127 GitHub stars~542 tokensUpdated 2 mo ago
    Auto-check passed
  • Pool

    opensage-agent/opensage-adk

    Run N tasks under a concurrency cap K via a sliding-window worker pool.

    127 GitHub stars~462 tokensUpdated 2 mo ago
    Auto-check passed
  • Create New Tool

    opensage-agent/opensage-adk

    Scaffold a new bashtools Skill under bashtools/newtools/. An agent skill from opensage-agent/opensage-adk.

    127 GitHub stars~302 tokensUpdated 2 mo ago
    Auto-check passed
  • Extract Crashes

    opensage-agent/opensage-adk

    Extract crash inputs from fuzzing output into a target directory.

    127 GitHub stars~215 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Call Paths

    opensage-agent/opensage-adk

    Get a path in the call graph from a source function to a specified destination function in the codebase.

    127 GitHub stars~272 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Callee

    opensage-agent/opensage-adk

    Tool to get the callee of a function in the codebase by function name and file path.

    127 GitHub stars~223 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Selective Instrument

What does Selective Instrument do?

Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk. Selective Instrument is an agent skill from opensage-agent/opensage-adk. Selective AFL++ instrumentation for directed fuzzing.

When should I use Selective Instrument?

Selective Instrument fits situations like: tasks that involve Fuzzing.

How do I install Selective Instrument in Claude Code?

Run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a claude-code`. Or copy the skill folder (src/opensage/bash_tools/fuzz/selective-instrument in opensage-agent/opensage-adk) into .claude/skills/selective-instrument in your project. Claude Code loads it when a task matches its description.

How do I install Selective Instrument in Codex?

Run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a codex`. Or copy the skill folder (src/opensage/bash_tools/fuzz/selective-instrument in opensage-agent/opensage-adk) into .agents/skills/selective-instrument in your project. Codex loads it when a task matches its description.

Can I use Selective Instrument in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/selective-instrument, .gemini/skills/selective-instrument, .github/skills/selective-instrument and .opencode/skills/selective-instrument in your project.

What does Selective Instrument need to run?

SKILL.md names no scripts, command-line tools or credentials: Selective Instrument is instructions for the agent only. Our summary lists: Python 3.

Does Selective Instrument access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Selective Instrument safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Selective Instrument use?

Selective Instrument is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Selective Instrument use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Selective Instrument?

Skills that share tags, products or a category with Selective Instrument: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 692 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Selective Instrument?

opensage-agent (a GitHub organization) maintains it in opensage-agent/opensage-adk, which has 127 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 4, 2026.

Source: opensage-agent/opensage-adk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.