Fizz
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk.
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .claude/skills/selective-instrument && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .claude/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrumentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .agents/skills/selective-instrument && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .agents/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .cursor/skills/selective-instrument && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .cursor/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/opensage-agent/opensage-adk.git --path src/opensage/bash_tools/fuzz/selective-instrument--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .gemini/skills/selective-instrument && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .gemini/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install opensage-agent/opensage-adk selective-instrumentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .github/skills/selective-instrument && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .github/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add opensage-agent/opensage-adk --skill selective-instrument -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install opensage-agent/opensage-adk selective-instrument --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/selective-instrument .opencode/skills/selective-instrument && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "selective-instrument" agent skill from https://github.com/opensage-agent/opensage-adk/tree/main/src/opensage/bash_tools/fuzz/selective-instrument into .opencode/skills/selective-instrument/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "selective-instrument", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
selective-instrumentSelective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk.
Selective Instrument is an agent skill from opensage-agent/opensage-adk. Selective AFL++ instrumentation for directed fuzzing. Agent writes target functions/files to /fuzz/allowlist.txt, recompiles with AFLLLVMALLOWLIST, then runs directed fuzzing to quickly reach the target region and collect characteristic seeds for further analysis or conventional fuzzing.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Fuzzing. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 54d6470. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Selective Instrument loads about 1.1k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 363 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from opensage-agent/opensage-adk at commit 54d6470, republished under its Apache-2.0 licence (© opensage-agent). 363 words, ~1,056 tokens.
.claude/skills/selective-instrument/SKILL.md (or your agent's skills folder).Directed fuzzing via AFL++ selective instrumentation. Only the specified functions or source files are instrumented, so AFL++ coverage feedback is limited to the target region. This makes the fuzzer converge quickly toward inputs that exercise those specific code paths.
Selective instrumentation is a directed fuzzing technique:
The instrumented binary is written to /out_selective (not /out), so the
original full-instrumented build is preserved.
Identify targets: Use static analysis, patch diff, or code review to determine which functions or files to focus on.
Write the allowlist: Create /fuzz/allowlist.txt in the fuzz sandbox
with one entry per line. Use run_terminal_command to write it:
cat > /fuzz/allowlist.txt << 'EOF'
fun:parse_header
fun:decode_payload
src:lib/parser.c
EOFAllowlist syntax (AFL_LLVM_ALLOWLIST format):
fun:<name> — instrument a specific function (wildcards OK: fun:parse_*)src:<path> — instrument all functions in a source filemod:<path> — instrument all functions in files under a directoryRecompile with selective instrumentation:
/bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh(Optional extra entries can be passed as arguments — they are appended to the existing allowlist file.)
Run directed fuzzing to collect seeds that reach the target:
/bash_tools/fuzz/selective-instrument/scripts/run_selective_fuzz.sh <fuzz_target> <duration_seconds> [seed_paths...] [--custom_mutator_path <path>] [--reset_output]Use the collected seeds: The fuzzing output (including seeds and
crashes) is in /fuzz/out_selective/. Feed interesting seeds into the
full-instrumented run-fuzzing-campaign, or use them for coverage
analysis, debugging, or PoC generation.
Reads /fuzz/allowlist.txt (which the agent must create beforehand),
optionally appends extra entries from arguments, then recompiles the project
with AFL_LLVM_ALLOWLIST into /out_selective.
# Typical: agent already wrote /fuzz/allowlist.txt
/bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh
# Or append extra entries via arguments
/bash_tools/fuzz/selective-instrument/scripts/selective_instrument.sh "fun:extra_func"Runs AFL++ using the selectively instrumented binary from /out_selective.
Output goes to /fuzz/out_selective/.
/bash_tools/fuzz/selective-instrument/scripts/run_selective_fuzz.sh <fuzz_target> <duration_seconds> [seed_paths...] [--custom_mutator_path <path>] [--reset_output]Type: str
Fuzz target binary name (looked up in /out_selective/<fuzz_target>).
Type: int
Fuzzing duration in seconds.
Type: list of strings
Optional seed file/dir paths.
Type: str
Optional path to a custom mutator python script.
Type: bool (default: false)
Reset output and start fresh.
fuzz
3600 seconds
© opensage-agent, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/opensage/bash_tools/fuzz/selective-instrument of opensage-agent/opensage-adk.
Open the folder on GitHubat commit 54d6470
Selective Instrument next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Selective Instrument this skillopensage-agent/opensage-adk | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Fizz Syncpashov/skills | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Research FuzzerARA-Labs/Agent-Native-Research-Artifact | 692 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None | |
| Binary Reverse Engineering Audittihanyin/REx-skill | 107 | — | ~5.1k | Automated safety check: Pass | MIT |
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
pashov/skills
Reconcile an existing Fizz harness with a changed source tree.
ARA-Labs/Agent-Native-Research-Artifact
Treat an open-ended investigation the way a fuzzer treats a program.
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
tihanyin/REx-skill
Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
opensage-agent/opensage-adk
Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).
opensage-agent/opensage-adk
Run N tasks under a concurrency cap K via a sliding-window worker pool.
opensage-agent/opensage-adk
Scaffold a new bashtools Skill under bashtools/newtools/. An agent skill from opensage-agent/opensage-adk.
opensage-agent/opensage-adk
Extract crash inputs from fuzzing output into a target directory.
opensage-agent/opensage-adk
Get a path in the call graph from a source function to a specified destination function in the codebase.
opensage-agent/opensage-adk
Tool to get the callee of a function in the codebase by function name and file path.
Categories
Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk. Selective Instrument is an agent skill from opensage-agent/opensage-adk. Selective AFL++ instrumentation for directed fuzzing.
Selective Instrument fits situations like: tasks that involve Fuzzing.
Run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a claude-code`. Or copy the skill folder (src/opensage/bash_tools/fuzz/selective-instrument in opensage-agent/opensage-adk) into .claude/skills/selective-instrument in your project. Claude Code loads it when a task matches its description.
Run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a codex`. Or copy the skill folder (src/opensage/bash_tools/fuzz/selective-instrument in opensage-agent/opensage-adk) into .agents/skills/selective-instrument in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add opensage-agent/opensage-adk --skill selective-instrument -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/selective-instrument, .gemini/skills/selective-instrument, .github/skills/selective-instrument and .opencode/skills/selective-instrument in your project.
SKILL.md names no scripts, command-line tools or credentials: Selective Instrument is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Selective Instrument is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Selective Instrument: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 692 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
opensage-agent (a GitHub organization) maintains it in opensage-agent/opensage-adk, which has 127 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 4, 2026.
Source: opensage-agent/opensage-adk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.