Official agent skill

Fuzzing Dictionary Builder

by trailofbits in trailofbits/skills

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Fuzzing Dictionary Builder

skills CLI
$ npx skills add trailofbits/skills --skill fuzzing-dictionary -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills fuzzing-dictionary --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-dictionary .claude/skills/fuzzing-dictionary && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fuzzing-dictionary
GitHub stars
7.4k
Token cost
~2.5k tokens
SKILL.md length
842 words
Files
3 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation.

  • Works in 3 steps: Create Dictionary File → Generate Dictionary Content → Pass Dictionary to Fuzzer
  • Fuzzing a parser, protocol handler or file format
  • SKILL.md covers Overview, When to Apply, Quick Reference and Step-by-Step, plus 7 more sections
  • Calls cargo

What it does

A dictionary is a text file of quoted tokens that the fuzzer injects into inputs, helping it reach code that blind mutation rarely hits. The skill explains the syntax (quoted strings, key-value entries, hex escapes for non-printable bytes and comments) and ways to generate content: prompting an LLM, grepping header files, running strings on a binary, or extracting terms from source and specifications.

Usage flags are given for libFuzzer (-dict), AFL++ (-x) and cargo-fuzz. The technique fits parsers for JSON or XML, protocol implementations such as HTTP and DNS, and file format handlers, especially when coverage stalls early or the target compares against fixed strings. It advises skipping it for pure algorithms, targets without keyword parsing and corpora that already reach high coverage.

When your agent uses it

  • Fuzzing a parser, protocol handler or file format
  • Coverage stalls at input validation
  • A target compares input against fixed strings or magic values
  • Extracting tokens from headers, binaries or specs for a dictionary

Example prompts

  • “Build a fuzzing dictionary for our HTTP request parser from the header file.”
  • “Run strings on ./target/parser and turn the output into a dictionary for AFL++.”
  • “Coverage is flat at the config parser. Create a dictionary and show the libFuzzer command.”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Create Dictionary File
  2. Generate Dictionary Content
  3. Pass Dictionary to Fuzzer

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • llvm.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fuzzing Dictionary Builder loads about 2.5k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 842 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 842 words, ~2,489 tokens.

Download SKILL.mdSave it as .claude/skills/fuzzing-dictionary/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
fuzzing-dictionary
description
Builds and applies fuzzing dictionaries so a fuzzer can produce the keywords, magic bytes, and tokens a target expects. Covers extracting tokens from source, headers, binaries, and specifications, dictionary syntax, and wiring one into libFuzzer or AFL++. Use when fuzzing a parser, protocol, or file format, when coverage stalls at input validation, or when a target compares against fixed strings.
type
technique

Fuzzing Dictionary

A fuzzing dictionary provides domain-specific tokens to guide the fuzzer toward interesting inputs. Instead of purely random mutations, the fuzzer incorporates known keywords, magic numbers, protocol commands, and format-specific strings that are more likely to reach deeper code paths in parsers, protocol handlers, and file format processors.

Overview

Dictionaries are text files containing quoted strings that represent meaningful tokens for your target. They help fuzzers bypass early validation checks and explore code paths that would be difficult to reach through blind mutation alone.

Key Concepts
ConceptDescription
Dictionary EntryA quoted string (e.g., "keyword") or key-value pair (e.g., kw="value")
Hex EscapesByte sequences like "\xF7\xF8" for non-printable characters
Token InjectionFuzzer inserts dictionary entries into generated inputs
Cross-Fuzzer FormatDictionary files work with libFuzzer, AFL++, and cargo-fuzz

When to Apply

Apply this technique when:

  • Fuzzing parsers (JSON, XML, config files)
  • Fuzzing protocol implementations (HTTP, DNS, custom protocols)
  • Fuzzing file format handlers (PNG, PDF, media codecs)
  • Coverage plateaus early without reaching deeper logic
  • Target code checks for specific keywords or magic values

Skip this technique when:

  • Fuzzing pure algorithms without format expectations
  • Target has no keyword-based parsing
  • Corpus already achieves high coverage

Quick Reference

TaskCommand/Pattern
Use with libFuzzer./fuzz -dict=./dictionary.dict ...
Use with AFL++afl-fuzz -x ./dictionary.dict ...
Use with cargo-fuzzcargo fuzz run fuzz_target -- -dict=./dictionary.dict
Extract from headergrep -o '".*"' header.h > header.dict
Generate from binarystrings ./binary | sed 's/^/"&/; s/$/&"/' > strings.dict

Step-by-Step

Step 1: Create Dictionary File

Create a text file with quoted strings on each line. Use comments (#) for documentation.

Example dictionary format:

conf
# Lines starting with '#' and empty lines are ignored.

# Adds "blah" (w/o quotes) to the dictionary.
kw1="blah"
# Use \\ for backslash and \" for quotes.
kw2="\"ac\\dc\""
# Use \xAB for hex values
kw3="\xF7\xF8"
# the name of the keyword followed by '=' may be omitted:
"foo\x0Abar"
Step 2: Generate Dictionary Content

Choose a generation method based on what's available:

From LLM: Prompt ChatGPT or Claude with:

text
A dictionary can be used to guide the fuzzer. Write me a dictionary file for fuzzing a <PNG parser>. Each line should be a quoted string or key-value pair like kw="value". Include magic bytes, chunk types, and common header values. Use hex escapes like "\xF7\xF8" for binary values.

From header files:

bash
grep -o '".*"' header.h > header.dict

From man pages (for CLI tools):

bash
man curl | grep -oP '^\s*(--|-)\K\S+' | sed 's/[,.]$//' | sed 's/^/"&/; s/$/&"/' | sort -u > man.dict

From binary strings:

bash
strings ./binary | sed 's/^/"&/; s/$/&"/' > strings.dict
Step 3: Pass Dictionary to Fuzzer

Use the appropriate flag for your fuzzer (see Quick Reference above).

Common Patterns

Pattern: Protocol Keywords

Use Case: Fuzzing HTTP or custom protocol handlers

Dictionary content:

conf
# HTTP methods
"GET"
"POST"
"PUT"
"DELETE"
"HEAD"

# Headers
"Content-Type"
"Authorization"
"Host"

# Protocol markers
"HTTP/1.1"
"HTTP/2.0"
Pattern: Magic Bytes and File Format Headers

Use Case: Fuzzing image parsers, media decoders, archive handlers

Dictionary content:

conf
# PNG magic bytes and chunks
png_magic="\x89PNG\r\n\x1a\n"
ihdr="IHDR"
plte="PLTE"
idat="IDAT"
iend="IEND"

# JPEG markers
jpeg_soi="\xFF\xD8"
jpeg_eoi="\xFF\xD9"
Pattern: Configuration File Keywords

Use Case: Fuzzing config file parsers (YAML, TOML, INI)

Dictionary content:

conf
# Common config keywords
"true"
"false"
"null"
"version"
"enabled"
"disabled"

# Section headers
"[general]"
"[network]"
"[security]"

Advanced Usage

Tips and Tricks
TipWhy It Helps
Combine multiple generation methodsLLM-generated keywords + strings from binary covers broad surface
Include boundary values"0", "-1", "2147483647" trigger edge cases
Add format delimiters:, =, {, } help fuzzer construct valid structures
Keep dictionaries focused50-200 entries perform better than thousands
Test dictionary effectivenessRun with and without dict, compare coverage
Auto-Generated Dictionaries (AFL++)

When using afl-clang-lto compiler, AFL++ automatically extracts dictionary entries from string comparisons in the binary. This happens at compile time via the AUTODICTIONARY feature.

Enable auto-dictionary:

bash
export AFL_LLVM_DICT2FILE=auto.dict
afl-clang-lto++ target.cc -o target
# Dictionary saved to auto.dict
afl-fuzz -x auto.dict -i in -o out -- ./target
Combining Multiple Dictionaries

Some fuzzers support multiple dictionary files:

bash
# AFL++ with multiple dictionaries
afl-fuzz -x keywords.dict -x formats.dict -i in -o out -- ./target

Anti-Patterns

Anti-PatternProblemCorrect Approach
Including full sentencesFuzzer needs atomic tokens, not proseBreak into individual keywords
Duplicating entriesWastes mutation budgetUse sort -u to deduplicate
Over-sized dictionariesSlows fuzzer, dilutes useful tokensKeep focused: 50-200 most relevant entries
Missing hex escapesNon-printable bytes become mangledUse \xXX for binary values
No commentsHard to maintain and auditDocument sections with # comments
Show full SKILL.md (331 more words)Show less

Tool-Specific Guidance

libFuzzer
bash
clang++ -fsanitize=fuzzer,address harness.cc -o fuzz
./fuzz -dict=./dictionary.dict corpus/

Integration tips:

  • Dictionary tokens are inserted/replaced during mutations
  • Combine with -max_len to control input size
  • Use -print_final_stats=1 to see dictionary effectiveness metrics
  • Dictionary entries longer than -max_len are ignored
AFL++
bash
afl-fuzz -x ./dictionary.dict -i input/ -o output/ -- ./target @@

Integration tips:

  • AFL++ supports multiple -x flags for multiple dictionaries
  • Use AFL_LLVM_DICT2FILE with afl-clang-lto for auto-generated dictionaries
  • Dictionary effectiveness shown in fuzzer stats UI
  • Tokens are used during deterministic and havoc stages
cargo-fuzz (Rust)
bash
cargo fuzz run fuzz_target -- -dict=./dictionary.dict

Integration tips:

  • cargo-fuzz uses libFuzzer backend, so all libFuzzer dict flags work
  • Place dictionary file in fuzz/ directory alongside harness
  • Reference from harness directory: cargo fuzz run target -- -dict=../dictionary.dict
go-fuzz (Go)

go-fuzz does not have built-in dictionary support, but you can manually seed the corpus with dictionary entries:

bash
# Convert dictionary to corpus files
grep -o '".*"' dict.txt | while read line; do
    echo -n "$line" | base64 > corpus/$(echo "$line" | md5sum | cut -d' ' -f1)
done

go-fuzz -bin=./target-fuzz.zip -workdir=.

Troubleshooting

IssueCauseSolution
Dictionary file not loadedWrong path or format errorCheck fuzzer output for dict parsing errors; verify file format
No coverage improvementDictionary tokens not relevantAnalyze target code for actual keywords; try different generation method
Syntax errors in dict fileUnescaped quotes or invalid escapesUse \\ for backslash, \" for quotes; validate with test run
Fuzzer ignores long entriesEntries exceed -max_lenKeep entries under max input length, or increase -max_len
Too many entries slow fuzzerDictionary too largePrune to 50-200 most relevant entries
Tools That Use This Technique
SkillHow It Applies
libfuzzerNative dictionary support via -dict= flag
aflppNative dictionary support via -x flag; auto-generation with AUTODICTIONARIES
cargo-fuzzUses libFuzzer backend, inherits -dict= support
SkillRelationship
fuzzing-corpusDictionaries complement corpus: corpus provides structure, dictionary provides keywords
coverage-analysisUse coverage data to validate dictionary effectiveness
harness-writingHarness structure determines which dictionary tokens are useful

Resources

Key External Resources

AFL++ Dictionaries Pre-built dictionaries for common formats (HTML, XML, JSON, SQL, etc.). Good starting point for format-specific fuzzing.

libFuzzer Dictionary Documentation Official libFuzzer documentation on dictionary format and usage. Explains token insertion strategy and performance implications.

Additional Examples

OSS-Fuzz Dictionaries Real-world dictionaries from Google's continuous fuzzing service. Search project directories for *.dict files to see production examples.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/fuzzing-dictionary of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Fuzzing Dictionary Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fuzzing Dictionary Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fuzzing Dictionary Builder this skilltrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Harness Design Fuzzingprovos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0
ClusterfuzzliteInternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clause
Stateful Invariant Testingaviggiano/security144—~2.8kAutomated safety check: PassMIT
Llvm Securityaftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.0

Similar skills

  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Stateful Invariant Testing

    aviggiano/security

    Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

    144 GitHub stars~2.8k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Llvm Security

    aftermathlabs/llvm-msvc

    Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

    438 GitHub stars~1.8k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    SecurityAuto-check: warnings

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Categories

Questions about Fuzzing Dictionary Builder

What does Fuzzing Dictionary Builder do?

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. A dictionary is a text file of quoted tokens that the fuzzer injects into inputs, helping it reach code that blind mutation rarely hits. The skill explains the syntax (quoted strings, key-value entries, hex escapes for non-printable bytes and comments) and ways to generate content: prompting an LLM, grepping header files, running strings on a binary, or extracting terms from source and specifications.

When should I use Fuzzing Dictionary Builder?

Fuzzing Dictionary Builder fits situations like: fuzzing a parser, protocol handler or file format; coverage stalls at input validation; A target compares input against fixed strings or magic values; extracting tokens from headers, binaries or specs for a dictionary.

How do I install Fuzzing Dictionary Builder in Claude Code?

Run `npx skills add trailofbits/skills --skill fuzzing-dictionary -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/fuzzing-dictionary in trailofbits/skills) into .claude/skills/fuzzing-dictionary in your project. Claude Code loads it when a task matches its description.

How do I install Fuzzing Dictionary Builder in Codex?

Run `npx skills add trailofbits/skills --skill fuzzing-dictionary -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/fuzzing-dictionary in trailofbits/skills) into .agents/skills/fuzzing-dictionary in your project. Codex loads it when a task matches its description.

Can I use Fuzzing Dictionary Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill fuzzing-dictionary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzzing-dictionary, .gemini/skills/fuzzing-dictionary, .github/skills/fuzzing-dictionary and .opencode/skills/fuzzing-dictionary in your project.

What does Fuzzing Dictionary Builder need to run?

Going by SKILL.md and its folder, Fuzzing Dictionary Builder needs the command-line tools its instructions call (cargo).

Does Fuzzing Dictionary Builder access the network?

SKILL.md names 2 domains. As links in the text: github.com and llvm.org. This is read from the text; nothing was executed.

Is Fuzzing Dictionary Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fuzzing Dictionary Builder use?

Fuzzing Dictionary Builder is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fuzzing Dictionary Builder use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fuzzing Dictionary Builder?

Skills that share tags, products or a category with Fuzzing Dictionary Builder: Fizz (pashov/skills, 1.2k stars), Harness Design Fuzzing (provos/ironcurtain, 613 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars) and Stateful Invariant Testing (aviggiano/security, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fuzzing Dictionary Builder?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.