Agent skill

Fuzz Testing

by s3s-project in s3s-project/s3s

Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.

Apache-2.0Auto-check passedSecurity

Install Fuzz Testing

skills CLI
$ npx skills add s3s-project/s3s --skill fuzz-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install s3s-project/s3s fuzz-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/s3s-project/s3s.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fuzz-testing .claude/skills/fuzz-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fuzz-testing
GitHub stars
311
Token cost
~838 tokens
SKILL.md length
482 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.

  • A target is added
  • SKILL.md covers The workspace, Run one target locally, Where the inputs come from and Adding a target, plus 2 more sections
  • Calls just and cargo
  • A scheduled run fails

What it does

Fuzz Testing is an agent skill from s3s-project/s3s. Add, run or schedule a fuzz target in this repository. Use when a target is added or renamed, when a scheduled run fails, when a crash has to be reproduced from an artifact, or when the fuzz budget and rotation are discussed.

Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. The licence is Apache-2.0.

When your agent uses it

  • A target is added
  • A scheduled run fails
  • A crash has to be reproduced from an artifact
  • The fuzz budget and rotation are discussed

Example prompts

  • “/fuzz-testing”

What it can do on your machine

Read from SKILL.md and the folder at commit 1e1c52e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fuzz Testing loads about 838 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~838

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from s3s-project/s3s at commit 1e1c52e, republished under its Apache-2.0 licence (© s3s-project). 482 words, ~838 tokens.

Download SKILL.mdSave it as .claude/skills/fuzz-testing/SKILL.md (or your agent's skills folder).
name
fuzz-testing
description
Add, run or schedule a fuzz target in this repository. Use when a target is added or renamed, when a scheduled run fails, when a crash has to be reproduced from an artifact, or when the fuzz budget and rotation are discussed.
license
Apache-2.0

Fuzz testing

The workspace

fuzz/ is its own workspace: the root just test and just lint never see it, so run its recipes from that directory. just ci-check is the gate — the formatting check, clippy with --cfg fuzzing on nightly, and the multipart_parser seed check — and it fails before anything fuzzes. A committed seed under fuzz/seeds/<target>/ is a promise: it encodes the outcome it was added for, so a seed whose result changes is a corpus bug and travels in the same commit as the fix it covers. How much of that a recipe can check depends on the target: just check-seeds covers multipart_parser, just gen-corpus validates the xml_bodies seeds while regenerating them, and the aws_chunked and syntax_parsers seeds have no checker at all, so those rest on review.

Run one target locally

From fuzz/, just fuzz <target> copies the committed seeds into fuzz/corpus/<target>/ and starts cargo-fuzz on nightly with ASan. Arguments after the target reach cargo-fuzz verbatim, so libFuzzer flags follow --; pass -timeout=25 so a hanging input becomes an artifact instead of a stuck run. To reproduce one artifact: just fuzz <target> <artifact>.

just ci-run <target> [FEATURES] [BUDGET] is what the scheduled run does: it merges the accumulated corpus down to the inputs that increase coverage, re-seeds, then fuzzes for BUDGET seconds (900 by default) with -timeout=25 -print_final_stats=1. Run it locally before blaming a scheduled failure on the target.

Where the inputs come from

Hand-written seeds are committed under fuzz/seeds/<target>/; the runtime corpus grows in fuzz/corpus/<target>/, which is local state and gitignored. just gen-corpus [--features minio] regenerates the xml_bodies seeds and validates each one, so a generator change belongs in the same commit as the seeds it rewrites. The second codegen variant needs the feature flag, and a target that exists in two variants is alternated by the scheduled rotation rather than fuzzed twice in one day.

Show full SKILL.md (174 more words)Show less

Adding a target

A target is a file under fuzz/fuzz_targets/ with a fuzz_target! entry point, driving the public API the way a test would. The roster comes from the fuzz manifest, so a new target joins the daily rotation without anyone editing a schedule; check cargo run -p xtask -- fuzz plan to see the day it lands on.

Reading the scheduled run

The daily workflow runs cargo run -p xtask -- fuzz run inside a fifteen-minute budget, one target per day, derived from the manifest. A failure is only interesting with its artifact: copy it out of the corpus, reproduce it locally, fix the cause, then keep the smallest failing input as a seed, and let just check-seeds guard it where that target has a checker.

What CI cannot show

A pull request runs fuzz-check, which builds the targets and validates the seeds but never fuzzes; only the daily run explores. A change that only a target covers stays unverified until that target has had its turn, and saying so is better than implying coverage.

© s3s-project, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/fuzz-testing of s3s-project/s3s.

Open the folder on GitHubat commit 1e1c52e

Compare with similar skills

Fuzz Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fuzz Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fuzz Testing this skills3s-project/s3s311—~838Automated safety check: PassApache-2.0
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Fizz Syncpashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT
Research FuzzerARA-Labs/Agent-Native-Research-Artifact690—~2.4kAutomated safety check: PassMIT
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone
Binary Reverse Engineering Audittihanyin/REx-skill105—~5.1kAutomated safety check: PassMIT

Similar skills

  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Research Fuzzer

    ARA-Labs/Agent-Native-Research-Artifact

    Treat an open-ended investigation the way a fuzzer treats a program.

    690 GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

    105 GitHub stars~5.1k tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    SecurityAuto-check passed

More from s3s-project/s3s

All 10 skills in this repo
  • Code Coverage

    s3s-project/s3s

    Measure and grow the line coverage of the s3s crate. An agent skill from s3s-project/s3s.

    311 GitHub stars~789 tokensUpdated today
    Auto-check passed
  • Gh Stack

    s3s-project/s3s

    Work with stacked pull requests in this repository using gh stack.

    311 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Code Review

    s3s-project/s3s

    Review a pull request or a proposed change to this repository.

    311 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Codegen

    s3s-project/s3s

    Change generated code in this repository. An agent skill from s3s-project/s3s.

    311 GitHub stars~726 tokensUpdated today
    Auto-check passed
  • Mutation Testing

    s3s-project/s3s

    Run or triage the mutation sweep in this repository. An agent skill from s3s-project/s3s.

    311 GitHub stars~917 tokensUpdated today
    Auto-check passed
  • Pull Request

    s3s-project/s3s

    Prepare a change for this repository as a pull request. An agent skill from s3s-project/s3s.

    311 GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Fuzz Testing

What does Fuzz Testing do?

Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s. Fuzz Testing is an agent skill from s3s-project/s3s. Add, run or schedule a fuzz target in this repository.

When should I use Fuzz Testing?

Fuzz Testing fits situations like: A target is added; A scheduled run fails; A crash has to be reproduced from an artifact; the fuzz budget and rotation are discussed.

How do I install Fuzz Testing in Claude Code?

Run `npx skills add s3s-project/s3s --skill fuzz-testing -a claude-code`. Or copy the skill folder (.agents/skills/fuzz-testing in s3s-project/s3s) into .claude/skills/fuzz-testing in your project. Claude Code loads it when a task matches its description.

How do I install Fuzz Testing in Codex?

Run `npx skills add s3s-project/s3s --skill fuzz-testing -a codex`. Or copy the skill folder (.agents/skills/fuzz-testing in s3s-project/s3s) into .agents/skills/fuzz-testing in your project. Codex loads it when a task matches its description.

Can I use Fuzz Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s3s-project/s3s --skill fuzz-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzz-testing, .gemini/skills/fuzz-testing, .github/skills/fuzz-testing and .opencode/skills/fuzz-testing in your project.

What does Fuzz Testing need to run?

Going by SKILL.md and its folder, Fuzz Testing needs the command-line tools its instructions call (just and cargo).

Does Fuzz Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fuzz Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fuzz Testing use?

Fuzz Testing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fuzz Testing use?

About 838 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fuzz Testing?

Skills that share tags, products or a category with Fuzz Testing: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 690 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fuzz Testing?

s3s-project (a GitHub organization) maintains it in s3s-project/s3s, which has 311 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.

Source: s3s-project/s3s on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.