Fizz
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .claude/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .claude/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .agents/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .agents/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .cursor/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .cursor/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SnailSploit/Claude-Red.git --path Skills/fuzzing/offensive-fuzzing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .gemini/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .gemini/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .github/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .github/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-fuzzing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills/fuzzing/offensive-fuzzing .opencode/skills/offensive-fuzzing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "offensive-fuzzing" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/fuzzing/offensive-fuzzing into .opencode/skills/offensive-fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-fuzzing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
offensive-fuzzingPractical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…
Offensive Fuzzing is an agent skill from SnailSploit/Claude-Red. Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage. Use when setting up or running fuzz campaigns against any target: file parsers, network protocols, kernel drivers, EDR engines, embedded firmware, or language runtimes.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Fuzzing. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargocmakemakegoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comllvm.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Offensive Fuzzing loads about 3k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 639 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
"sshkey": "/path/to/id_rsa",Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 639 words, ~2,963 tokens.
.claude/skills/offensive-fuzzing/SKILL.md (or your agent's skills folder).| Type | Coverage | Speed | Tools |
|---|---|---|---|
| BlackBox | Poor | Fast | Peach, Boofuzz |
| GreyBox | Good | Fast | AFL++, Honggfuzz, libFuzzer, WinAFL |
| Snapshot | Good | Fastest | Nyx, wtf, Snapchange |
| WhiteBox | Best | Slow | KLEE, QSYM, SymSan |
| Ensemble | Best | Fast | AFL++ + Honggfuzz + libFuzzer |
GreyBox sub-variants: Directed (AFLGo, UAFuzz), Grammar (AFLSmart, Tlspuffin), Concolic (QSYM, Driller), Kernel (syzkaller, kAFL, wtf).
Research target → Choose analyses → Build harness → Seed corpus → Instrument → Fuzz → Triage crashes → Reportcopy_from_user — DMA-BUF ops, page fault handlers, VM operation structs, allocation callbacks# AFL++ (preferred for GreyBox)
CC=afl-clang-fast CXX=afl-clang-fast++ cmake -DCMAKE_BUILD_TYPE=Release .. && make -j
# libFuzzer + ASan/UBSan (C/C++)
cmake -DCMAKE_CXX_FLAGS="-fsanitize=fuzzer,address,undefined -O1 -g" ..
# CmpLog build for hard compares
AFL_LLVM_CMPLOG=1 CC=afl-clang-fast CXX=afl-clang-fast++ make clean allWindows (MSVC): Project Properties → C/C++ → Address Sanitizer: Yes (/fsanitize=address)
libFuzzer (C++):
#include <cstdint>
#include <cstddef>
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
parse_or_process(data, size);
return 0;
}Honggfuzz HF_ITER (persistent mode — preferred for large targets):
#include "honggfuzz.h"
int main(int argc, char** argv) {
initialize_target(); // runs once
for (;;) {
size_t len; uint8_t *buf;
HF_ITER(&buf, &len);
FILE* s = fmemopen(buf, len, "r");
target_function(s);
fclose(s);
reset_target_state();
}
}AFL++ persistent mode (__AFL_LOOP):
while (__AFL_LOOP(10000)) {
// re-read input and process
}macOS IPC (Mach message fuzzing):
void *lib_handle = dlopen("libexample.dylib", RTLD_LAZY);
pFunction = dlsym(lib_handle, "DesiredFunction");afl-cmin -i raw_corpus -o seeds -- ./target @@afl-tmin -i crash -o crash.min -- ./target @@AFL++ parallel (primary + secondary with cmplog):
afl-fuzz -M f1 -i seeds -o findings -x dict.txt -- ./target @@
afl-fuzz -S s1 -i seeds -o findings -c 0 -- ./target @@libFuzzer:
./target_libfuzzer corpus/ -max_total_time=3600 -workers=4Binary-only (QEMU):
afl-fuzz -Q -i seeds -o findings -- target.exe @@Snapshot (AFL++ Nyx):
NYX_MODE=1 AFL_MAP_SIZE=1048576 afl-fuzz -i seeds -o findings -- ./target_nyx @@Ensemble (AFL++ + Honggfuzz sharing corpus):
# Terminal 1
afl-fuzz -M fuzzer1 -i seeds -o sync_dir -- ./target @@
# Terminal 2
../honggfuzz/honggfuzz -i sync_dir/fuzzer1/queue -W sync_dir/hfuzz \
--linux_perf_ipt_block -t 10 -- ./target ___FILE___If progress stalls:
-c 0 on AFL++ secondaries-x dict.txt or AFL_TOKEN_FILEAFL_MAP_SIZE=1048576, -L 0 for MOpt scheduler# 1. Minimize
afl-tmin -i crash -o crash.min -- ./target @@
# 2. Symbolize
ASAN_OPTIONS=abort_on_error=1:symbolize=1 ./target crash.min 2>asan.log
# 3. Hash + bucket
./cov-tool --bbids ./target crash.min > cov.hash
./bucket.py --key "$(cat cov.hash)" --log asan.log --out triage/Sanitizer env quick reference:
ASAN_OPTIONS=abort_on_error=1:symbolize=1:detect_stack_use_after_return=1
UBSAN_OPTIONS=print_stacktrace=1:halt_on_error=1
TSAN_OPTIONS=halt_on_error=1:history_size=7
MSAN_OPTIONS=poison_in_dtor=1:track_origins=2| Bug Class | Oracle |
|---|---|
| Memory safety | ASan, HWASan (AArch64, lower overhead) |
| Uninitialized reads | MSan |
| Concurrency | TSan |
| Undefined behavior | UBSan |
| Type safety | TypeSan |
| Heap hardening | Scudo Hardened Allocator |
| Logic bugs | Differential / idempotency oracles |
| Kernel memory | KASAN, KMSAN, KCSAN |
| Kernel UB | KUBSan (CONFIG_UBSAN_TRAP=y) |
| CFI | KCFI (-fsanitize=kcfi, Clang 18) |
| Binary-only | QASAN (QEMU+ASan), DynamoRIO |
Property oracle patterns:
f(x) == f(f(x)){
"target": "linux/arm64",
"http": ":56700",
"workdir": "/path/to/workdir",
"kernel_obj": "/path/to/kernel",
"image": "/path/to/rootfs.ext3",
"sshkey": "/path/to/id_rsa",
"procs": 8,
"enable_syscalls": ["openat$module_name", "ioctl$IOCTL_CMD", "mmap"],
"type": "qemu",
"vm": { "count": 4, "cpu": 2, "mem": 2048 }
}enable_syscalls to deepen coverage on specific subsystemssyz-extract to pull constants for custom modulesCONFIG_KASAN=y, CONFIG_KCFI=y, CONFIG_DEBUG_INFO_BTF=ykcov filters and syz_cover_filter to direct coverageTUN/TAP + pseudo-syscalls (syz_emit_ethernet)./scripts/decode_stacktrace.sh vmlinux ... < dmesg.logsyzkaller repro:
syz-execprog -repeat=0 -procs=1 -cover=0 -debug target.reproWTF snapshot harness skeleton (mpengine.dll / mini-filter):
g_Backend->SetBreakpoint("nt!KeBugCheck2", [](Backend_t *Backend) {
const uint64_t BCode = Backend->GetArg(0);
Backend->Stop(Crash_t(fmt::format("crash-{:#x}", BCode)));
});FilterConnectionPort fuzzing:
HANDLE hPort;
FilterConnectCommunicationPort(L"\\PortName", 0, NULL, 0, NULL, &hPort);
FilterSendMessage(hPort, fuzzData, sizeof(fuzzData), NULL, 0, &bytesReturned);IOCTL fuzzing pattern:
HANDLE hDev = CreateFile(L"\\\\.\\DeviceName", GENERIC_READ|GENERIC_WRITE, ...);
DeviceIoControl(hDev, ioctlCode, inputBuf, inputLen, outBuf, outLen, &ret, NULL);DRIVER_VERIFIER_DETECTED_VIOLATION (0xc4), IRQL_NOT_LESS_OR_EQUAL (0xa).symfix; !analyze -v; k; !heap -p -a @raxCross-platform mpengine.dll on Linux (loadlibrary + HF_ITER + Intel PT):
// Bypass Lua VM to avoid stability issues
insert_function_redirect((void*)luaV_execute_address, my_lua_exec, HOOK_REPLACE_FUNCTION);
for (;;) {
HF_ITER(&buf, &len);
ScanDescriptor.UserPtr = fmemopen(buf, len, "r");
__rsignal(&KernelHandle, RSIG_SCAN_STREAMBUFFER, &ScanParams, sizeof ScanParams);
}# Full Rust fuzzing pipeline
cargo test # 1. property tests
cargo +nightly miri test # 2. UB via interpreter
cargo +nightly careful test # 3. runtime bounds checks
cargo fuzz run fuzz_target_1 -- -max_total_time=3600 # 4. libFuzzer crashes
RUSTFLAGS="--cfg loom" cargo test --release # 5. concurrency (if needed)
cargo fuzz coverage fuzz_target_1 # 6. coverage reportFocus unsafe blocks on: Vec::from_raw_parts, unchecked indexing, transmute size mismatches, pointer arithmetic, FFI integer truncation.
go test -fuzz=Fuzz -run=^$ ./...cargo-fuzz or honggfuzz-rs__builtin_return_address(0) for PC tracking)wasmtime-fuzz, wafl for differential fuzzing across V8/Wasmer/Wasmtime- name: Build with afl-clang-fast
run: CC=afl-clang-fast make -j
- name: Fuzz (smoke, 15 min)
run: timeout 15m afl-fuzz -i seeds -o findings -- ./target @@ || true
- name: Upload crashes
if: always()
uses: actions/upload-artifact@v4
with:
path: findings/**/crashes/*Use ClusterFuzzLite for persistent continuous fuzzing; cache corpora between runs.
Linux:
ulimit -c unlimited && sysctl -w kernel.core_pattern=core.%e.%p
gdb -q ./target core.* -ex 'bt' -ex 'info reg' -ex q
addr2line -e ./target 0xDEADBEEFWindows:
# Enable local dumps
New-Item 'HKLM:\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps' -Force
# PageHeap
gflags /p /enable target.exe /fullKernel KASAN/KMSAN:
dmesg -T | egrep -i 'kasan|kmsan' -A 60
./scripts/decode_stacktrace.sh vmlinux /lib/modules/$(uname -r)/build < dmesg.logReproducibility: pin CPU governor, disable ASLR only where safe, fix RNG seeds, save input sequences in persistent mode, record binary hashes and sanitizer options with every crash.
| Tool | Use Case |
|---|---|
| AFL++ | General GreyBox, CmpLog, MOpt, Nyx |
| Honggfuzz | Intel PT, crash detection, HF_ITER |
| libFuzzer | In-process, source available |
| syzkaller | Linux/Windows kernel syscall fuzzing |
| wtf | Snapshot fuzzing, Windows targets |
| Nyx | AFL++ snapshot mode (Intel PT) |
| Snapchange | AWS snapshot fuzzing |
| LibAFL | Custom Rust fuzzing framework |
| AFLGo | Directed fuzzing to target BB/function |
| kAFL | Kernel + OS fuzzing |
| Jackalope | Binary coverage-guided (Windows/macOS) |
| cargo-fuzz | Rust libFuzzer integration |
| Atheris | Python fuzzing |
| Nautilus | Grammar-based fuzzing |
| AFLTriage | Automated crash triage |
| afl-cov | Coverage analysis for AFL++ |
| ClusterFuzz | Distributed fuzzing infrastructure |
© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in Skills/fuzzing/offensive-fuzzing of SnailSploit/Claude-Red.
Open the folder on GitHubat commit 739512a
Offensive Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Offensive Fuzzing this skillSnailSploit/Claude-Red | 7.3k | — | ~3k | Automated safety check: Warn | MIT | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Fizz Syncpashov/skills | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Research FuzzerARA-Labs/Agent-Native-Research-Artifact | 690 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None | |
| Binary Reverse Engineering Audittihanyin/REx-skill | 105 | — | ~5.1k | Automated safety check: Pass | MIT |
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
pashov/skills
Reconcile an existing Fizz harness with a changed source tree.
ARA-Labs/Agent-Native-Research-Artifact
Treat an open-ended investigation the way a fuzzer treats a program.
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
tihanyin/REx-skill
Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
SnailSploit/Claude-Red
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
SnailSploit/Claude-Red
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
SnailSploit/Claude-Red
Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.
SnailSploit/Claude-Red
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…
SnailSploit/Claude-Red
Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…
Categories
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…. Offensive Fuzzing is an agent skill from SnailSploit/Claude-Red. Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage.
Offensive Fuzzing fits situations like: running fuzz campaigns against any target: file parsers; network protocols; embedded firmware; language runtimes.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a claude-code`. Or copy the skill folder (Skills/fuzzing/offensive-fuzzing in SnailSploit/Claude-Red) into .claude/skills/offensive-fuzzing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a codex`. Or copy the skill folder (Skills/fuzzing/offensive-fuzzing in SnailSploit/Claude-Red) into .agents/skills/offensive-fuzzing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-fuzzing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-fuzzing, .gemini/skills/offensive-fuzzing, .github/skills/offensive-fuzzing and .opencode/skills/offensive-fuzzing in your project.
Going by SKILL.md and its folder, Offensive Fuzzing needs the command-line tools its instructions call (cargo, cmake, make and go). Our summary lists: Python 3.
SKILL.md names 2 domains. As links in the text: github.com and llvm.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Offensive Fuzzing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Offensive Fuzzing: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 690 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.
Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.