Fizz
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.
$ npx skills add s3s-project/s3s --skill fuzz-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install s3s-project/s3s fuzz-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fuzz-testing .claude/skills/fuzz-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .claude/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add s3s-project/s3s --skill fuzz-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install s3s-project/s3s fuzz-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/fuzz-testing .agents/skills/fuzz-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .agents/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add s3s-project/s3s --skill fuzz-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install s3s-project/s3s fuzz-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/fuzz-testing .cursor/skills/fuzz-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .cursor/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/s3s-project/s3s.git --path .agents/skills/fuzz-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add s3s-project/s3s --skill fuzz-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install s3s-project/s3s fuzz-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/fuzz-testing .gemini/skills/fuzz-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .gemini/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install s3s-project/s3s fuzz-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add s3s-project/s3s --skill fuzz-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/fuzz-testing .github/skills/fuzz-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .github/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add s3s-project/s3s --skill fuzz-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install s3s-project/s3s fuzz-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/fuzz-testing .opencode/skills/fuzz-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fuzz-testing" agent skill from https://github.com/s3s-project/s3s/tree/main/.agents/skills/fuzz-testing into .opencode/skills/fuzz-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fuzz-testingAdd, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.
Fuzz Testing is an agent skill from s3s-project/s3s. Add, run or schedule a fuzz target in this repository. Use when a target is added or renamed, when a scheduled run fails, when a crash has to be reproduced from an artifact, or when the fuzz budget and rotation are discussed.
Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Fuzzing. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 1e1c52e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
justcargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fuzz Testing loads about 838 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 482 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from s3s-project/s3s at commit 1e1c52e, republished under its Apache-2.0 licence (© s3s-project). 482 words, ~838 tokens.
.claude/skills/fuzz-testing/SKILL.md (or your agent's skills folder).fuzz/ is its own workspace: the root just test and just lint never see it, so run its recipes from that directory. just ci-check is the gate — the formatting check, clippy with --cfg fuzzing on nightly, and the multipart_parser seed check — and it fails before anything fuzzes. A committed seed under fuzz/seeds/<target>/ is a promise: it encodes the outcome it was added for, so a seed whose result changes is a corpus bug and travels in the same commit as the fix it covers. How much of that a recipe can check depends on the target: just check-seeds covers multipart_parser, just gen-corpus validates the xml_bodies seeds while regenerating them, and the aws_chunked and syntax_parsers seeds have no checker at all, so those rest on review.
From fuzz/, just fuzz <target> copies the committed seeds into fuzz/corpus/<target>/ and starts cargo-fuzz on nightly with ASan. Arguments after the target reach cargo-fuzz verbatim, so libFuzzer flags follow --; pass -timeout=25 so a hanging input becomes an artifact instead of a stuck run. To reproduce one artifact: just fuzz <target> <artifact>.
just ci-run <target> [FEATURES] [BUDGET] is what the scheduled run does: it merges the accumulated corpus down to the inputs that increase coverage, re-seeds, then fuzzes for BUDGET seconds (900 by default) with -timeout=25 -print_final_stats=1. Run it locally before blaming a scheduled failure on the target.
Hand-written seeds are committed under fuzz/seeds/<target>/; the runtime corpus grows in fuzz/corpus/<target>/, which is local state and gitignored. just gen-corpus [--features minio] regenerates the xml_bodies seeds and validates each one, so a generator change belongs in the same commit as the seeds it rewrites. The second codegen variant needs the feature flag, and a target that exists in two variants is alternated by the scheduled rotation rather than fuzzed twice in one day.
A target is a file under fuzz/fuzz_targets/ with a fuzz_target! entry point, driving the public API the way a test would. The roster comes from the fuzz manifest, so a new target joins the daily rotation without anyone editing a schedule; check cargo run -p xtask -- fuzz plan to see the day it lands on.
The daily workflow runs cargo run -p xtask -- fuzz run inside a fifteen-minute budget, one target per day, derived from the manifest. A failure is only interesting with its artifact: copy it out of the corpus, reproduce it locally, fix the cause, then keep the smallest failing input as a seed, and let just check-seeds guard it where that target has a checker.
A pull request runs fuzz-check, which builds the targets and validates the seeds but never fuzzes; only the daily run explores. A change that only a target covers stays unverified until that target has had its turn, and saying so is better than implying coverage.
© s3s-project, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/fuzz-testing of s3s-project/s3s.
Open the folder on GitHubat commit 1e1c52e
Fuzz Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fuzz Testing this skills3s-project/s3s | 311 | — | ~838 | Automated safety check: Pass | Apache-2.0 | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Fizz Syncpashov/skills | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Research FuzzerARA-Labs/Agent-Native-Research-Artifact | 690 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None | |
| Binary Reverse Engineering Audittihanyin/REx-skill | 105 | — | ~5.1k | Automated safety check: Pass | MIT |
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
pashov/skills
Reconcile an existing Fizz harness with a changed source tree.
ARA-Labs/Agent-Native-Research-Artifact
Treat an open-ended investigation the way a fuzzer treats a program.
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
tihanyin/REx-skill
Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
s3s-project/s3s
Measure and grow the line coverage of the s3s crate. An agent skill from s3s-project/s3s.
s3s-project/s3s
Work with stacked pull requests in this repository using gh stack.
s3s-project/s3s
Review a pull request or a proposed change to this repository.
s3s-project/s3s
Change generated code in this repository. An agent skill from s3s-project/s3s.
s3s-project/s3s
Run or triage the mutation sweep in this repository. An agent skill from s3s-project/s3s.
s3s-project/s3s
Prepare a change for this repository as a pull request. An agent skill from s3s-project/s3s.
Categories
Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s. Fuzz Testing is an agent skill from s3s-project/s3s. Add, run or schedule a fuzz target in this repository.
Fuzz Testing fits situations like: A target is added; A scheduled run fails; A crash has to be reproduced from an artifact; the fuzz budget and rotation are discussed.
Run `npx skills add s3s-project/s3s --skill fuzz-testing -a claude-code`. Or copy the skill folder (.agents/skills/fuzz-testing in s3s-project/s3s) into .claude/skills/fuzz-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add s3s-project/s3s --skill fuzz-testing -a codex`. Or copy the skill folder (.agents/skills/fuzz-testing in s3s-project/s3s) into .agents/skills/fuzz-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s3s-project/s3s --skill fuzz-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzz-testing, .gemini/skills/fuzz-testing, .github/skills/fuzz-testing and .opencode/skills/fuzz-testing in your project.
Going by SKILL.md and its folder, Fuzz Testing needs the command-line tools its instructions call (just and cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fuzz Testing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 838 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fuzz Testing: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 690 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
s3s-project (a GitHub organization) maintains it in s3s-project/s3s, which has 311 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.
Source: s3s-project/s3s on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.