Official agent skill

Aflpp

by trailofbits in trailofbits/skills

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Aflpp

skills CLI
$ npx skills add trailofbits/skills --skill aflpp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills aflpp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/aflpp .claude/skills/aflpp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aflpp
GitHub stars
7.4k
Token cost
~5.6k tokens
SKILL.md length
2,025 words
Files
3 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

  • Works in 2 steps: More executions per second (scales… → Asymmetrical fuzzing (e.g., one ASan…
  • Scaling fuzzing across cores
  • SKILL.md covers When to Use, Quick Start, Installation and Writing a Harness, plus 3 more sections
  • Calls docker, bash and apt; reaches github.com and raw.githubusercontent.com

What it does

Aflpp is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. Covers instrumentation modes, parallel main and secondary campaigns, persistent mode, corpus minimization, and crash triage. Use when scaling fuzzing across cores, fuzzing a mature C/C++ codebase, reading the afl-fuzz status screen, or moving on after libFuzzer has plateaued.

Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including assets (for example `agents/openai.yaml`).

It sits in Security, covering Fuzzing. It works with C++ and Docker. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Scaling fuzzing across cores
  • Fuzzing a mature C/C++ codebase
  • Reading the afl-fuzz status screen
  • Moving on after libFuzzer has plateaued

Example prompts

  • “/aflpp”

Requirements

  • Docker

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. More executions per second (scales linearly with physical cores)
  2. Asymmetrical fuzzing (e.g., one ASan job, rest without sanitizers)

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • bash
    • apt
    • git
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • raw.githubusercontent.com

    Also links to:

    • youtube.com
    • aflplus.plus
    • blog.ritsec.club
    • usenix.org
    • blog.trailofbits.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aflpp loads about 5.6k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 2,025 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 2,025 words, ~5,595 tokens.

Download SKILL.mdSave it as .claude/skills/aflpp/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
aflpp
description
Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. Covers instrumentation modes, parallel main and secondary campaigns, persistent mode, corpus minimization, and crash triage. Use when scaling fuzzing across cores, fuzzing a mature C/C++ codebase, reading the afl-fuzz status screen, or moving on after libFuzzer has plateaued.
type
fuzzer

AFL++

AFL++ is a fork of the original AFL fuzzer that offers better fuzzing performance and more advanced features while maintaining stability. A major benefit over libFuzzer is that AFL++ has stable support for running fuzzing campaigns on multiple cores, making it ideal for large-scale fuzzing efforts.

When to Use

FuzzerBest ForComplexity
AFL++Multi-core fuzzing, diverse mutations, mature projectsMedium
libFuzzerQuick setup, single-threaded, simple harnessesLow
LibAFLCustom fuzzers, research, advanced use casesHigh

Choose AFL++ when:

  • You need multi-core fuzzing to maximize throughput
  • Your project can be compiled with Clang or GCC
  • You want diverse mutation strategies and mature tooling
  • libFuzzer has plateaued and you need more coverage
  • You're fuzzing production codebases that benefit from parallel execution

Quick Start

c++
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
    // Call your code with fuzzer-provided data
    check_buf((char*)data, size);
    return 0;
}

Compile and run:

bash
# Setup AFL++ wrapper script first (see Installation)
./afl++ docker afl-clang-fast++ -DNO_MAIN=1 -O2 -fsanitize=fuzzer harness.cc main.cc -o fuzz
mkdir seeds && echo "aaaa" > seeds/minimal_seed
./afl++ docker afl-fuzz -i seeds -o out -- ./fuzz

Installation

AFL++ has many dependencies including LLVM, Python, and Rust. We recommend using a current Debian or Ubuntu distribution for fuzzing with AFL++.

MethodWhen to UseSupported Compilers
Ubuntu/Debian reposRecent Ubuntu, basic features onlyUbuntu 23.10: Clang 14 & GCC 13<br>Debian 12: Clang 14 & GCC 12
Docker (from Docker Hub)Specific AFL++ version, Apple Silicon supportAs of 4.35c: Clang 19 & GCC 11
Docker (from source)Test unreleased features, apply patchesConfigurable in Dockerfile
From sourceAvoid Docker, need specific patchesAdjustable via LLVM_CONFIG env var
Ubuntu/Debian

Prior to installing afl++, check the clang version dependency of the packge with apt-cache show afl++, and install the matching lld version (e.g., lld-17).

bash
apt install afl++ lld-17
Docker (from Docker Hub)
bash
docker pull aflplusplus/aflplusplus:stable
Docker (from source)
bash
git clone --depth 1 --branch stable https://github.com/AFLplusplus/AFLplusplus
cd AFLplusplus
docker build -t aflplusplus .
From source

Refer to the Dockerfile for Ubuntu version requirements and dependencies. Set LLVM_CONFIG to specify Clang version (e.g., llvm-config-18).

Wrapper Script Setup

Create a wrapper script to run AFL++ on host or Docker:

bash
cat <<'EOF' > ./afl++
#!/bin/sh
AFL_VERSION="${AFL_VERSION:-"stable"}"
case "$1" in
   host)
        shift
        bash -c "$*"
        ;;
    docker)
        shift
        /usr/bin/env docker run -i \
            --privileged \
            -v ./:/src \
            --rm \
            --name "afl_fuzzing_$$" \
            "aflplusplus/aflplusplus:$AFL_VERSION" \
            bash -c "cd /src && bash -c \"$*\""
        ;;
    *)
        echo "Usage: $0 {host|docker}"
        exit 1
        ;;
esac
EOF
chmod +x ./afl++

The examples below use docker mode, apart from the system configuration commands that have to reach the host kernel. Swap in host to run any of them against an AFL++ installed on the machine itself. The wrapper joins everything after the mode argument into a single shell string, so quoting does not survive: an argument containing a space (-x "my dict.dict") arrives word-split. Rename such files without spaces, or edit the wrapper for that run.

The missing -t is deliberate. docker run -ti aborts with the input device is not a TTY whenever stdin is not a terminal, which covers CI jobs and anything an agent or script drives. afl-fuzz notices there is no terminal and prints plain status lines in place of the full-screen UI. A program that insists on a terminal, such as watch, has to run on the host side of the wrapper instead. $$ expands to the wrapper's PID, so parallel instances get distinct container names rather than colliding on a single afl_fuzzing. docker ps truncates the COMMAND column, so every row looks alike; use docker ps --no-trunc to tell the instances apart before stopping one.

Security Warning: The afl-system-config and afl-persistent-config scripts require root privileges and disable OS security features. Do not fuzz on production systems or your development environment. Use a dedicated VM instead.

System Configuration

Run after each reboot for up to 15% more executions per second:

bash
./afl++ host afl-system-config

afl-system-config tunes the kernel it runs against, so run it on the machine that hosts the campaign. ./afl++ docker afl-system-config reaches the same settings through the wrapper's --privileged container, which is the only route when AFL++ is installed via Docker alone.

For maximum performance, disable kernel security mitigations (requires grub bootloader, not supported in Docker):

bash
./afl++ host afl-persistent-config
update-grub
reboot
./afl++ host afl-system-config

Verify with cat /proc/cmdline - output should include mitigations=off.

Writing a Harness

Harness Structure

AFL++ supports libFuzzer-style harnesses:

c++
#include <stdint.h>
#include <stddef.h>

extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
    // 1. Validate input size if needed
    if (size < MIN_SIZE || size > MAX_SIZE) return 0;

    // 2. Call target function with fuzz data
    target_function(data, size);

    // 3. Return 0 (non-zero reserved for future use)
    return 0;
}
Harness Rules
DoDon't
Reset global state between runsRely on state from previous runs
Handle edge cases gracefullyExit on invalid input
Keep harness deterministicUse random number generators
Free allocated memoryCreate memory leaks
Validate input sizesProcess unbounded input

See Also: For detailed harness writing techniques, patterns for handling complex inputs, and advanced strategies, see the fuzz-harness-writing technique skill.

Compilation

AFL++ offers multiple compilation modes with different trade-offs.

Compilation Mode Decision Tree

Choose your compilation mode:

  • LTO mode (afl-clang-lto): Best performance and instrumentation. Try this first.
  • LLVM mode (afl-clang-fast): Fall back if LTO fails to compile.
  • GCC plugin (afl-gcc-fast): For projects requiring GCC.
Basic Compilation (LLVM mode)
bash
./afl++ docker afl-clang-fast++ -DNO_MAIN=1 -O2 -fsanitize=fuzzer harness.cc main.cc -o fuzz
GCC Compilation
bash
./afl++ docker afl-g++-fast -DNO_MAIN=1 -O2 -fsanitize=fuzzer harness.cc main.cc -o fuzz

Important: GCC version must match the version used to compile the AFL++ GCC plugin.

With Sanitizers
bash
./afl++ docker AFL_USE_ASAN=1 afl-clang-fast++ -DNO_MAIN=1 -O2 -fsanitize=fuzzer harness.cc main.cc -o fuzz

See Also: For detailed sanitizer configuration, common issues, and advanced flags, see the address-sanitizer and undefined-behavior-sanitizer technique skills.

Build Flags

Note that -g is not necessary, it is added by default by the AFL++ compilers.

FlagPurpose
-DNO_MAIN=1Skip main function when using libFuzzer harness
-O2Production optimization level (recommended for fuzzing)
-fsanitize=fuzzerEnable libFuzzer compatibility mode and adds the fuzzer runtime when linking executable
-fsanitize=fuzzer-no-linkInstrument without linking fuzzer runtime (for static libraries and object files)

Corpus Management

Creating Initial Corpus

AFL++ requires at least one non-empty seed file:

bash
mkdir seeds
echo "aaaa" > seeds/minimal_seed

For real projects, gather representative inputs:

  • Download example files for the format you're fuzzing
  • Extract test cases from the project's test suite
  • Use minimal valid inputs for your file format
Corpus Minimization

After a campaign, minimize the corpus to keep only unique coverage:

bash
./afl++ docker afl-cmin -i out/default/queue -o minimized_corpus -- ./fuzz

See Also: For corpus creation strategies, dictionaries, and seed selection, see the fuzzing-corpus technique skill.

Running Campaigns

Basic Run
bash
./afl++ docker afl-fuzz -i seeds -o out -- ./fuzz
Setting Environment Variables
bash
./afl++ docker AFL_FAST_CAL=1 afl-fuzz -i seeds -o out -- ./fuzz
Interpreting Output

AFL++ reports these statistics either way, but how you read them depends on the mode. The wrapper's docker run -i gives the container no TTY, so afl-fuzz drops the full-screen UI and writes plain status lines to the log instead — the fields below appear there, and in state/<instance>/fuzzer_stats. To get the interactive UI, run host mode in a terminal, or add -t to the wrapper for a run you are watching by hand.

OutputMeaning
execs/secExecution speed - higher is better
cycles doneNumber of queue passes completed
corpus countNumber of unique test cases in queue
saved crashesNumber of unique crashes found
stability% of stable edges (should be near 100%)
Output Directory Structure
text
out/default/
├── cmdline          # How was the SUT invoked?
├── crashes/         # Inputs that crash the SUT
│   └── id:000000,sig:06,src:000002,time:286,execs:13105,op:havoc,rep:4
├── hangs/           # Inputs that hang the SUT
├── queue/           # Test cases reproducing final fuzzer state
│   ├── id:000000,time:0,execs:0,orig:minimal_seed
│   └── id:000001,src:000000,time:0,execs:8,op:havoc,rep:6,+cov
├── fuzzer_stats     # Campaign statistics
└── plot_data        # Data for plotting
Analyzing Results

View live campaign statistics:

bash
./afl++ docker afl-whatsup out

Create coverage plots. The aflplusplus image already ships gnuplot-nox; in host mode, install gnuplot first with apt install gnuplot.

bash
./afl++ docker afl-plot out/default out_graph/
Re-executing Test Cases

Pass one of the filenames from out/default/crashes/:

bash
./afl++ docker ./fuzz out/default/crashes/id:000000,sig:06,src:000002,time:286,execs:13105,op:havoc,rep:4
Fuzzer Options
OptionPurpose
-G 4000Maximum test input length (default: 1048576 bytes)
-t 1000Timeout in milliseconds for each test case (default: 1000ms)
-m 1000Memory limit in megabytes (default: 0 = unlimited)
-x ./dict.dictUse dictionary file to guide mutations

Environment Variables That Matter

AFL++ has many environment variables, but most are niche. These are the ones that matter in practice.

Always Set These
bash
# Every campaign should use tmpfs — SSDs will thank you, and it's faster
AFL_TMPDIR=/dev/shm

AFL_TMPDIR is a free performance win with no downsides — not setting it wears out your SSD and slows fuzzing.

Slow Targets
bash
# Speeds up calibration ~2.5x — use when targets are slow (e.g., >10 ms/exec)
AFL_FAST_CAL=1

AFL_FAST_CAL reduces calibration time with negligible precision loss. Recommended specifically for slow targets where calibration would otherwise take a long time.

Multi-Core Campaigns
bash
# On the primary (-M) instance only — needed for afl-cmin, not for fuzzing itself
AFL_FINAL_SYNC=1

# On all instances — cache test cases in memory (default: 50 MB, good range: 50-250 MB)
AFL_TESTCACHE_SIZE=100

AFL_FINAL_SYNC tells the primary instance to do a final import from all secondaries when stopping. This does not affect the fuzzing process itself — it only matters when you later run afl-cmin for corpus minimization, ensuring the primary's queue has the full combined corpus. AFL_TESTCACHE_SIZE caches test cases in memory to reduce disk I/O; the default is 50 MB and values between 50-250 MB work well for most campaigns.

CI/Automated Fuzzing
bash
# Fail fast if fuzzing isn't finding anything
AFL_EXIT_ON_TIME=3600  # 1 hour with no new paths = stop

# Or run until "done" (all queue entries processed)
AFL_EXIT_WHEN_DONE=1

# Headless environments
AFL_NO_UI=1

Unbounded fuzzing in CI wastes resources. Set time limits or use exit conditions.

Show full SKILL.md (814 more words)Show less
Variables to Avoid
VariableWhy Skip It
AFL_NO_ARITHCan hurt coverage on binary formats, but may be useful for text-based targets
AFL_SHUFFLE_QUEUEOnly for exotic setups, usually harmful
AFL_DISABLE_TRIMTrimming is valuable, don't disable without reason

Multi-Core Fuzzing

AFL++ excels at multi-core fuzzing with two major advantages:

  1. More executions per second (scales linearly with physical cores)
  2. Asymmetrical fuzzing (e.g., one ASan job, rest without sanitizers)
Starting a Campaign

Start the primary fuzzer (in background):

bash
./afl++ docker afl-fuzz -M primary -i seeds -o state -- ./fuzz 1>primary.log 2>primary.error </dev/null &

Start secondary fuzzers (as many as you have cores):

bash
./afl++ docker afl-fuzz -S secondary01 -i seeds -o state -- ./fuzz 1>secondary01.log 2>secondary01.error </dev/null &
./afl++ docker afl-fuzz -S secondary02 -i seeds -o state -- ./fuzz 1>secondary02.log 2>secondary02.error </dev/null &

The </dev/null is required, not decorative. docker run -i keeps the client reading its own stdin, and a backgrounded process that reads the terminal is sent SIGTTIN, whose default action stops it — so without the redirect these jobs show up as Stopped in jobs and never fuzz.

Monitoring Multi-Core Campaigns

List all running jobs:

bash
jobs

View live statistics. watch needs a terminal that docker run -i does not give it, so wrap the whole invocation instead of running watch inside the container. Every tick starts a container, which is why the interval is 5 seconds rather than 1:

bash
watch -n5 --color ./afl++ docker afl-whatsup state/
Stopping All Fuzzers
bash
kill $(jobs -p)

Coverage Analysis

AFL++ automatically tracks coverage through edge instrumentation. Coverage information is stored in fuzzer_stats and plot_data.

Measuring Coverage

Use afl-plot to visualize coverage over time:

bash
./afl++ docker afl-plot out/default out_graph/
Improving Coverage
  • Use dictionaries for format-aware fuzzing
  • Run longer campaigns (cycles_wo_finds indicates plateau)
  • Try different mutation strategies with multi-core fuzzing
  • Analyze coverage gaps and add targeted seed inputs

See Also: For detailed coverage analysis techniques, identifying coverage gaps, and systematic coverage improvement, see the coverage-analysis technique skill.

CMPLOG

CMPLOG/RedQueen is the best path constraint solving mechanism available in any fuzzer. To enable it, the fuzz target needs to be instrumented for it. Before building the fuzzing target set the environment variable:

bash
./afl++ docker AFL_LLVM_CMPLOG=1 make

No special action is needed for compiling and linking the harness.

To run a fuzzer instance with a CMPLOG instrumented fuzzing target, add -c0 to the command like arguments:

bash
./afl++ docker afl-fuzz -c0 -S cmplog -i seeds -o state -- ./fuzz 1>cmplog.log 2>cmplog.error </dev/null &

Sanitizer Integration

Sanitizers are essential for finding memory corruption bugs that don't cause immediate crashes.

AddressSanitizer (ASan)
bash
./afl++ docker AFL_USE_ASAN=1 afl-clang-fast++ -DNO_MAIN=1 -O2 -fsanitize=fuzzer harness.cc main.cc -o fuzz

Note: Memory limit (-m) is not supported with ASan due to 20TB virtual memory reservation.

UndefinedBehaviorSanitizer (UBSan)
bash
./afl++ docker AFL_USE_UBSAN=1 afl-clang-fast++ -DNO_MAIN=1 -O2 -fsanitize=fuzzer,undefined harness.cc main.cc -o fuzz
Common Sanitizer Issues
IssueSolution
ASan slows fuzzingUse only 1 ASan job in multi-core setup
Stack exhaustionIncrease stack with ASAN_OPTIONS=stack_size=...
GCC version mismatchEnsure system GCC matches AFL++ plugin version

See Also: For comprehensive sanitizer configuration and troubleshooting, see the address-sanitizer technique skill.

Advanced Usage

Tips and Tricks
TipWhy It Helps
Use LLVMFuzzerTestOneInput harnesses where possibleIf a fuzzing campaign has at least 85% stability then this is the most efficient fuzzing style. If not then try standard input or file input fuzzing
Use dictionariesHelps fuzzer discover format-specific keywords and magic bytes
Set realistic timeoutsPrevents false positives from system load
Limit input sizeLarger inputs don't necessarily explore more space
Monitor stabilityLow stability indicates non-deterministic behavior
Standard Input Fuzzing

AFL++ can fuzz programs reading from stdin without a libFuzzer harness:

bash
./afl++ docker afl-clang-fast++ -O2 main_stdin.c -o fuzz_stdin
./afl++ docker afl-fuzz -i seeds -o out -- ./fuzz_stdin

This is slower than persistent mode but requires no harness code.

File Input Fuzzing

For programs that read files, use @@ placeholder:

bash
./afl++ docker afl-clang-fast++ -O2 main_file.c -o fuzz_file
./afl++ docker afl-fuzz -i seeds -o out -- ./fuzz_file @@

For better performance, use fmemopen to create file descriptors from memory.

Argument Fuzzing

Fuzz command-line arguments using argv-fuzz-inl.h:

c++
#include <stdio.h>
#include <stdlib.h>
#include <string.h>

#ifdef __AFL_COMPILER
#include "argv-fuzz-inl.h"
#endif

void check_buf(char *buf, size_t buf_len) {
    if(buf_len > 0 && buf[0] == 'a') {
        if(buf_len > 1 && buf[1] == 'b') {
            if(buf_len > 2 && buf[2] == 'c') {
                abort();
            }
        }
    }
}

int main(int argc, char *argv[]) {
#ifdef __AFL_COMPILER
    AFL_INIT_ARGV();
#endif

    if (argc < 2) {
        fprintf(stderr, "Usage: %s <input_string>\n", argv[0]);
        return 1;
    }

    char *input_buf = argv[1];
    size_t len = strlen(input_buf);
    check_buf(input_buf, len);
    return 0;
}

Download the header:

bash
curl -O https://raw.githubusercontent.com/AFLplusplus/AFLplusplus/stable/utils/argv_fuzzing/argv-fuzz-inl.h

Compile and run:

bash
./afl++ docker afl-clang-fast++ -O2 main_arg.c -o fuzz_arg
./afl++ docker afl-fuzz -i seeds -o out -- ./fuzz_arg
Performance Tuning
SettingImpact
CPU core countLinear scaling with physical cores
Persistent mode10-20x faster than fork server
-G input size limitSmaller = faster, but may miss bugs
ASan ratio1 ASan job per 4-8 non-ASan jobs

Troubleshooting

ProblemCauseSolution
Low exec/sec (<1k)Not using persistent modeCreate a LLVMFuzzerTestOneInput style harness
Low stability (<85%)Non-deterministic codeFuzz a program via stdin or file inputs, or create such a harness
GCC plugin errorGCC version mismatchEnsure system GCC matches AFL++ build and install gcc-$GCC_VERSION-plugin-dev
No crashes foundNeed sanitizersRecompile with AFL_USE_ASAN=1
Memory limit exceededASan uses 20TB virtualRemove -m flag when using ASan
Docker performance lossVirtualization overheadUse bare metal or VM for production fuzzing
Technique Skills
SkillUse Case
fuzz-harness-writingDetailed guidance on writing effective harnesses
address-sanitizerMemory error detection during fuzzing
undefined-behavior-sanitizerDetect undefined behavior bugs
fuzzing-corpusBuilding and managing seed corpora
fuzzing-dictionariesCreating dictionaries for format-aware fuzzing
SkillWhen to Consider
libfuzzerQuick prototyping, single-threaded fuzzing is sufficient
libaflNeed custom mutators or research-grade features

Resources

Key External Resources

AFL++ GitHub Repository Official repository with comprehensive documentation, examples, and issue tracker.

Fuzzing in Depth Advanced documentation by the AFL++ team covering instrumentation modes, optimization techniques, and advanced use cases.

AFL++ Under The Hood Technical deep-dive into AFL++ internals, mutation strategies, and coverage tracking mechanisms.

AFL++: Combining Incremental Steps of Fuzzing Research Research paper describing AFL++ architecture and performance improvements over original AFL.

Video Resources

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/aflpp of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Aflpp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aflpp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aflpp this skilltrailofbits/skills7.4k—~5.6kAutomated safety check: PassCC-BY-SA-4.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Harness Design Fuzzingprovos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0
ClusterfuzzliteInternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clause
Audit Native Memory Safetycyberful/cyberful134—~829Automated safety check: PassAGPL-3.0
Fuzzingmohitmishra786/low-level-dev-skills253—~2.1kAutomated safety check: PassMIT

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

    134 GitHub stars~829 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Fuzzing

    mohitmishra786/low-level-dev-skills

    Fuzzing skill for automated input-driven bug finding in C/C++.

    253 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Check Cross Runtime

    ayutaz/piper-plus

    Python canonical (src/pythonrun/piperplus/, src/python/pipertrain/, src/python/g2p/piperplusg2p/) を変更した PR で、 ONNX I/O 以外の追随漏れ (phonemizer / config schema / CLI flag / data 形式 / API 変更) を 7 ランタイム +…

    218 GitHub stars~3.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Aflpp

What does Aflpp do?

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. Aflpp is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

When should I use Aflpp?

Aflpp fits situations like: scaling fuzzing across cores; fuzzing a mature C/C++ codebase; reading the afl-fuzz status screen; moving on after libFuzzer has plateaued.

How do I install Aflpp in Claude Code?

Run `npx skills add trailofbits/skills --skill aflpp -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/aflpp in trailofbits/skills) into .claude/skills/aflpp in your project. Claude Code loads it when a task matches its description.

How do I install Aflpp in Codex?

Run `npx skills add trailofbits/skills --skill aflpp -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/aflpp in trailofbits/skills) into .agents/skills/aflpp in your project. Codex loads it when a task matches its description.

Can I use Aflpp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill aflpp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aflpp, .gemini/skills/aflpp, .github/skills/aflpp and .opencode/skills/aflpp in your project.

What does Aflpp need to run?

Going by SKILL.md and its folder, Aflpp needs the command-line tools its instructions call (docker, bash, apt, git and curl). Our summary lists: Docker.

Does Aflpp access the network?

SKILL.md names 7 domains. In commands or code: github.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. As links in the text: youtube.com, aflplus.plus, blog.ritsec.club, usenix.org and blog.trailofbits.com. This is read from the text; nothing was executed.

Is Aflpp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aflpp use?

Aflpp is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aflpp use?

About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aflpp?

Skills that share tags, products or a category with Aflpp: Code Audit (3stoneBrother/code-audit, 893 stars), Harness Design Fuzzing (provos/ironcurtain, 613 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars) and Audit Native Memory Safety (cyberful/cyberful, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aflpp?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.