Official agent skill

cargo-fuzz Rust Fuzzing

by trailofbits in trailofbits/skills

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install cargo-fuzz Rust Fuzzing

skills CLI
$ npx skills add trailofbits/skills --skill cargo-fuzz -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills cargo-fuzz --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/cargo-fuzz .claude/skills/cargo-fuzz && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cargo-fuzz
GitHub stars
7.4k
Token cost
~2.9k tokens
SKILL.md length
710 words
Files
3 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

  • Fuzzing a Rust crate that uses Cargo
  • SKILL.md covers When to Use, Quick Start, Installation and Writing a Harness, plus 6 more sections
  • Calls cargo, rustc and git; reaches github.com and commons.wikimedia.org
  • Writing a fuzz_target! harness for a parsing function

What it does

cargo-fuzz drives libFuzzer through a Cargo subcommand that sets compile flags and supports sanitizers such as AddressSanitizer. The skill explains installing the nightly toolchain, running cargo fuzz init, editing the generated harness under fuzz/fuzz_targets and starting a run with cargo +nightly fuzz run.

Harness guidance says to move code into a library crate, use the fuzz_target! macro, handle Result errors instead of panicking and keep the harness deterministic. The skill also covers Arbitrary-derived structured inputs, sanitizer options, cargo fuzz coverage and replaying a crash artifact, and it compares cargo-fuzz with AFL++ and LibAFL. It suits crates with unsafe blocks or FFI.

When your agent uses it

  • Fuzzing a Rust crate that uses Cargo
  • Writing a fuzz_target! harness for a parsing function
  • Exercising unsafe blocks or FFI code in Rust
  • Triaging and reproducing a cargo fuzz crash

Example prompts

  • “Set up cargo-fuzz for this crate and write a harness for the parse_config function.”
  • “Add structured fuzzing inputs with Arbitrary for our packet decoder.”
  • “Reproduce the crash artifact in fuzz/artifacts and explain the cause.”

Requirements

  • Rust and Cargo installed through rustup
  • The nightly Rust toolchain
  • The cargo-fuzz subcommand

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • rustc
    • git
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • commons.wikimedia.org

    Also links to:

    • rustup.rs
    • rust-fuzz.github.io
    • docs.rs

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

cargo-fuzz Rust Fuzzing loads about 2.9k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 710 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 710 words, ~2,943 tokens.

Download SKILL.mdSave it as .claude/skills/cargo-fuzz/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
cargo-fuzz
description
Sets up and runs cargo-fuzz, the standard fuzzing tool for Cargo-based Rust projects. Covers cargo fuzz init, the nightly toolchain requirement, fuzz_target! harnesses, Arbitrary-derived structured inputs, sanitizer options, cargo fuzz coverage, and reproducing a crash artifact. Use when fuzzing a Rust crate, writing a fuzz_target!, exercising unsafe blocks or FFI in Rust, or triaging a cargo fuzz crash.
type
fuzzer

cargo-fuzz

cargo-fuzz is the de facto choice for fuzzing Rust projects when using Cargo. It uses libFuzzer as the backend and provides a convenient Cargo subcommand that automatically enables relevant compilation flags for your Rust project, including support for sanitizers like AddressSanitizer.

When to Use

cargo-fuzz is currently the primary and most mature fuzzing solution for Rust projects using Cargo.

FuzzerBest ForComplexity
cargo-fuzzCargo-based Rust projects, quick setupLow
AFL++Multi-core fuzzing, non-Cargo projectsMedium
LibAFLCustom fuzzers, research, advanced use casesHigh

Choose cargo-fuzz when:

  • Your project uses Cargo (required)
  • You want simple, quick setup with minimal configuration
  • You need integrated sanitizer support
  • You're fuzzing Rust code with or without unsafe blocks

Quick Start

rust
#![no_main]

use libfuzzer_sys::fuzz_target;

fn harness(data: &[u8]) {
    your_project::check_buf(data);
}

fuzz_target!(|data: &[u8]| {
    harness(data);
});

Initialize and run:

bash
cargo fuzz init
# Edit fuzz/fuzz_targets/fuzz_target_1.rs with your harness
cargo +nightly fuzz run fuzz_target_1

Installation

cargo-fuzz requires the nightly Rust toolchain because it uses features only available in nightly.

Prerequisites
  • Rust and Cargo installed via rustup
  • Nightly toolchain
Linux/macOS
bash
# Install nightly toolchain
rustup install nightly

# Install cargo-fuzz
cargo install cargo-fuzz
Verification
bash
cargo +nightly --version
cargo fuzz --version

Writing a Harness

Project Structure

cargo-fuzz works best when your code is structured as a library crate. If you have a binary project, split your main.rs into:

text
src/main.rs  # Entry point (main function)
src/lib.rs   # Code to fuzz (public functions)
Cargo.toml

Initialize fuzzing:

bash
cargo fuzz init

This creates:

text
fuzz/
├── Cargo.toml
└── fuzz_targets/
    └── fuzz_target_1.rs
Harness Structure
rust
#![no_main]

use libfuzzer_sys::fuzz_target;

fn harness(data: &[u8]) {
    // 1. Validate input size if needed
    if data.is_empty() {
        return;
    }

    // 2. Call target function with fuzz data
    your_project::target_function(data);
}

fuzz_target!(|data: &[u8]| {
    harness(data);
});
Harness Rules
DoDon't
Structure code as library crateKeep everything in main.rs
Use fuzz_target! macroWrite custom main function
Handle Result::Err gracefullyPanic on expected errors
Keep harness deterministicUse random number generators

See Also: For detailed harness writing techniques and structure-aware fuzzing with the arbitrary crate, see the fuzz-harness-writing technique skill.

Structure-Aware Fuzzing

cargo-fuzz integrates with the arbitrary crate for structure-aware fuzzing:

rust
// In your library crate
use arbitrary::Arbitrary;

#[derive(Debug, Arbitrary)]
pub struct Name {
    data: String
}
rust
// In your fuzz target
#![no_main]
use libfuzzer_sys::fuzz_target;

fuzz_target!(|data: your_project::Name| {
    data.check_buf();
});

Add to your library's Cargo.toml:

toml
[dependencies]
arbitrary = { version = "1", features = ["derive"] }

Running Campaigns

Basic Run
bash
cargo +nightly fuzz run fuzz_target_1
Without Sanitizers (Safe Rust)

If your project doesn't use unsafe Rust, disable sanitizers for 2x performance boost:

bash
cargo +nightly fuzz run --sanitizer none fuzz_target_1

Check if your project uses unsafe code:

bash
cargo install cargo-geiger
cargo geiger
Re-executing Test Cases
bash
# Run a specific test case (e.g., a crash)
cargo +nightly fuzz run fuzz_target_1 fuzz/artifacts/fuzz_target_1/crash-<hash>

# Run all corpus entries without fuzzing
cargo +nightly fuzz run fuzz_target_1 fuzz/corpus/fuzz_target_1 -- -runs=0
Using Dictionaries
bash
cargo +nightly fuzz run fuzz_target_1 -- -dict=./dict.dict
Interpreting Output
OutputMeaning
NEWNew coverage-increasing input discovered
pulsePeriodic status update
INITEDFuzzer initialized successfully
Crash with stack traceBug found, saved to fuzz/artifacts/

Corpus location: fuzz/corpus/fuzz_target_1/ Crashes location: fuzz/artifacts/fuzz_target_1/

Sanitizer Integration

AddressSanitizer (ASan)

ASan is enabled by default and detects memory errors:

bash
cargo +nightly fuzz run fuzz_target_1
Disabling Sanitizers

For pure safe Rust (no unsafe blocks in your code or dependencies):

bash
cargo +nightly fuzz run --sanitizer none fuzz_target_1

Performance impact: ASan adds ~2x overhead. Disable for safe Rust to improve fuzzing speed.

Checking for Unsafe Code
bash
cargo install cargo-geiger
cargo geiger

See Also: For detailed sanitizer configuration, flags, and troubleshooting, see the address-sanitizer technique skill.

Coverage Analysis

cargo-fuzz integrates with Rust's coverage tools to analyze fuzzing effectiveness.

Prerequisites
bash
rustup toolchain install nightly --component llvm-tools-preview
cargo install cargo-binutils
cargo install rustfilt
Generating Coverage Reports
bash
# Generate coverage data from corpus
cargo +nightly fuzz coverage fuzz_target_1

Create coverage generation script:

bash
cat <<'EOF' > ./generate_html
#!/bin/sh
if [ $# -lt 1 ]; then
    echo "Error: Name of fuzz target is required."
    echo "Usage: $0 fuzz_target [sources...]"
    exit 1
fi
FUZZ_TARGET="$1"
shift
SRC_FILTER="$@"
TARGET=$(rustc -vV | sed -n 's|host: ||p')
cargo +nightly cov -- show -Xdemangler=rustfilt \
  "target/$TARGET/coverage/$TARGET/release/$FUZZ_TARGET" \
  -instr-profile="fuzz/coverage/$FUZZ_TARGET/coverage.profdata"  \
  -show-line-counts-or-regions -show-instantiations  \
  -format=html -o fuzz_html/ $SRC_FILTER
EOF
chmod +x ./generate_html

Generate HTML report:

bash
./generate_html fuzz_target_1 src/lib.rs

HTML report saved to: fuzz_html/

See Also: For detailed coverage analysis techniques and systematic coverage improvement, see the coverage-analysis technique skill.

Advanced Usage

Show full SKILL.md (292 more words)Show less
Tips and Tricks
TipWhy It Helps
Start with a seed corpusDramatically speeds up initial coverage discovery
Use --sanitizer none for safe Rust2x performance improvement
Check coverage regularlyIdentifies gaps in harness or seed corpus
Use dictionaries for parsersHelps overcome magic value checks
Structure code as libraryRequired for cargo-fuzz integration
libFuzzer Options

Pass options to libFuzzer after --:

bash
# See all options
cargo +nightly fuzz run fuzz_target_1 -- -help=1

# Set timeout per run
cargo +nightly fuzz run fuzz_target_1 -- -timeout=10

# Use dictionary
cargo +nightly fuzz run fuzz_target_1 -- -dict=dict.dict

# Limit maximum input size
cargo +nightly fuzz run fuzz_target_1 -- -max_len=1024
Multi-Core Fuzzing
bash
# Experimental forking support (not recommended)
cargo +nightly fuzz run --jobs 1 fuzz_target_1

Note: The multi-core fuzzing feature is experimental and not recommended. For parallel fuzzing, consider running multiple instances manually or using AFL++.

Real-World Examples

Example: ogg Crate

The ogg crate parses Ogg media container files. Parsers are excellent fuzzing targets because they handle untrusted data.

bash
# Clone and initialize
git clone https://github.com/RustAudio/ogg.git
cd ogg/
cargo fuzz init

Harness at fuzz/fuzz_targets/fuzz_target_1.rs:

rust
#![no_main]

use ogg::{PacketReader, PacketWriter};
use ogg::writing::PacketWriteEndInfo;
use std::io::Cursor;
use libfuzzer_sys::fuzz_target;

fn harness(data: &[u8]) {
    let mut pck_rdr = PacketReader::new(Cursor::new(data.to_vec()));
    pck_rdr.delete_unread_packets();

    let output = Vec::new();
    let mut pck_wtr = PacketWriter::new(Cursor::new(output));

    if let Ok(_) = pck_rdr.read_packet() {
        if let Ok(r) = pck_rdr.read_packet() {
            match r {
                Some(pck) => {
                    let inf = if pck.last_in_stream() {
                        PacketWriteEndInfo::EndStream
                    } else if pck.last_in_page() {
                        PacketWriteEndInfo::EndPage
                    } else {
                        PacketWriteEndInfo::NormalPacket
                    };
                    let stream_serial = pck.stream_serial();
                    let absgp_page = pck.absgp_page();
                    let _ = pck_wtr.write_packet(
                        pck.data, stream_serial, inf, absgp_page
                    );
                }
                None => return,
            }
        }
    }
}

fuzz_target!(|data: &[u8]| {
    harness(data);
});

Seed the corpus:

bash
mkdir fuzz/corpus/fuzz_target_1/
curl -o fuzz/corpus/fuzz_target_1/320x240.ogg \
  https://commons.wikimedia.org/wiki/File:320x240.ogg

Run:

bash
cargo +nightly fuzz run fuzz_target_1

Analyze coverage:

bash
cargo +nightly fuzz coverage fuzz_target_1
./generate_html fuzz_target_1 src/lib.rs

Troubleshooting

ProblemCauseSolution
"requires nightly" errorUsing stable toolchainUse cargo +nightly fuzz
Slow fuzzing performanceASan enabled for safe RustAdd --sanitizer none flag
"cannot find binary"No library crateMove code from main.rs to lib.rs
Sanitizer compilation issuesWrong nightly versionTry different nightly: rustup install nightly-2024-01-01
Low coverageMissing seed corpusAdd sample inputs to fuzz/corpus/fuzz_target_1/
Magic value not foundNo dictionaryCreate dictionary file with magic values
Technique Skills
SkillUse Case
fuzz-harness-writingStructure-aware fuzzing with arbitrary crate
address-sanitizerUnderstanding ASan output and configuration
coverage-analysisMeasuring and improving fuzzing effectiveness
fuzzing-corpusBuilding and managing seed corpora
fuzzing-dictionariesCreating dictionaries for format-aware fuzzing
SkillWhen to Consider
libfuzzerFuzzing C/C++ code with similar workflow
aflppMulti-core fuzzing or non-Cargo Rust projects
libaflAdvanced fuzzing research or custom fuzzer development

Resources

Rust Fuzz Book - cargo-fuzz Official documentation for cargo-fuzz covering installation, usage, and advanced features.

arbitrary crate documentation Guide to structure-aware fuzzing with automatic derivation for Rust types.

cargo-fuzz GitHub Repository Source code, issue tracker, and examples for cargo-fuzz.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/cargo-fuzz of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg

Open the folder on GitHubat commit 82fe822

Compare with similar skills

cargo-fuzz Rust Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

cargo-fuzz Rust Fuzzing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
cargo-fuzz Rust Fuzzing this skilltrailofbits/skills7.4k—~2.9kAutomated safety check: PassCC-BY-SA-4.0
Audit Native Memory Safetycyberful/cyberful135—~829Automated safety check: PassAGPL-3.0
Rust Securitymohitmishra786/low-level-dev-skills253—~1.6kAutomated safety check: PassMIT
Solana Audit Flowmtarcure/claude-vibe-squad163—~1.4kAutomated safety check: PassMIT
GreptimeDB Fuzz CI Failure InvestigationGreptimeTeam/greptimedb6.7k—~4.4kAutomated safety check: PassApache-2.0
Directed Test Input GeneratorArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

    135 GitHub stars~829 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Rust Security

    mohitmishra786/low-level-dev-skills

    Rust security skill for supply chain safety and memory-safe development.

    253 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Solana Audit Flow

    mtarcure/claude-vibe-squad

    A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…

    163 GitHub stars~1.4k tokensUpdated 18 days ago
    SecurityAuto-check passed
  • Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code.

    6.7k GitHub stars~4.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Directed Test Input Generator

    ArabelaTso/Skills-4-SE

    Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

    253 GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Kernel Testing

    mohitmishra786/low-level-dev-skills

    Linux kernel testing skill for KUnit, kselftest, syzkaller, and LTP.

    253 GitHub stars~1.4k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about cargo-fuzz Rust Fuzzing

What does cargo-fuzz Rust Fuzzing do?

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. cargo-fuzz drives libFuzzer through a Cargo subcommand that sets compile flags and supports sanitizers such as AddressSanitizer. The skill explains installing the nightly toolchain, running cargo fuzz init, editing the generated harness under fuzz/fuzz_targets and starting a run with cargo +nightly fuzz run.

When should I use cargo-fuzz Rust Fuzzing?

cargo-fuzz Rust Fuzzing fits situations like: fuzzing a Rust crate that uses Cargo; writing a fuzz_target! harness for a parsing function; exercising unsafe blocks or FFI code in Rust; triaging and reproducing a cargo fuzz crash.

How do I install cargo-fuzz Rust Fuzzing in Claude Code?

Run `npx skills add trailofbits/skills --skill cargo-fuzz -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/cargo-fuzz in trailofbits/skills) into .claude/skills/cargo-fuzz in your project. Claude Code loads it when a task matches its description.

How do I install cargo-fuzz Rust Fuzzing in Codex?

Run `npx skills add trailofbits/skills --skill cargo-fuzz -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/cargo-fuzz in trailofbits/skills) into .agents/skills/cargo-fuzz in your project. Codex loads it when a task matches its description.

Can I use cargo-fuzz Rust Fuzzing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill cargo-fuzz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cargo-fuzz, .gemini/skills/cargo-fuzz, .github/skills/cargo-fuzz and .opencode/skills/cargo-fuzz in your project.

What does cargo-fuzz Rust Fuzzing need to run?

Going by SKILL.md and its folder, cargo-fuzz Rust Fuzzing needs the command-line tools its instructions call (cargo, rustc, git and curl). Our summary lists: Rust and Cargo installed through rustup; The nightly Rust toolchain; The cargo-fuzz subcommand.

Does cargo-fuzz Rust Fuzzing access the network?

SKILL.md names 5 domains. In commands or code: github.com and commons.wikimedia.org; the agent is likely to contact these when it follows the instructions. As links in the text: rustup.rs, rust-fuzz.github.io and docs.rs. This is read from the text; nothing was executed.

Is cargo-fuzz Rust Fuzzing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does cargo-fuzz Rust Fuzzing use?

cargo-fuzz Rust Fuzzing is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does cargo-fuzz Rust Fuzzing use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to cargo-fuzz Rust Fuzzing?

Skills that share tags, products or a category with cargo-fuzz Rust Fuzzing: Audit Native Memory Safety (cyberful/cyberful, 135 stars), Rust Security (mohitmishra786/low-level-dev-skills, 253 stars), Solana Audit Flow (mtarcure/claude-vibe-squad, 163 stars) and GreptimeDB Fuzz CI Failure Investigation (GreptimeTeam/greptimedb, 6.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains cargo-fuzz Rust Fuzzing?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.