Audit Native Memory Safety
cyberful/cyberful
Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.
Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills fuzzing-obstacles --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .claude/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .claude/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstaclesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills fuzzing-obstacles --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .agents/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .agents/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills fuzzing-obstacles --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .cursor/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .cursor/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/testing-handbook-skills/skills/fuzzing-obstacles--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills fuzzing-obstacles --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .gemini/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .gemini/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills fuzzing-obstaclesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .github/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .github/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill fuzzing-obstacles -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills fuzzing-obstacles --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/fuzzing-obstacles .opencode/skills/fuzzing-obstacles && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fuzzing-obstacles" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/fuzzing-obstacles into .opencode/skills/fuzzing-obstacles/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing-obstacles", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fuzzing-obstaclesPatches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.
Programs that verify checksums or hashes, seed random generators from the clock or run heavy validation stop fuzzers from making progress. The skill shows how to locate the blocking check and neutralize it behind a fuzzing build flag using conditional compilation, so the production build keeps its original behavior. A quick-reference table covers C and C++ along with Rust.
It treats false positives as the main risk, meaning crashes that could never occur in production because the check was bypassed. It also lists when to skip patching: a good seed corpus or dictionary solves the problem, the validation is simple enough to learn, structure-aware fuzzing already handles it, or too many false positives would result. Determinism, the same input giving the same behavior, is called out as critical.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comllvm.orgdoc.rust-lang.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fuzzing Obstacle Patcher loads about 4k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 1,401 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,401 words, ~3,955 tokens.
.claude/skills/fuzzing-obstacles/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Codebases often contain anti-fuzzing patterns that prevent effective coverage. Checksums, global state (like time-seeded PRNGs), and validation checks can block the fuzzer from exploring deeper code paths. This technique shows how to patch your System Under Test (SUT) to bypass these obstacles during fuzzing while preserving production behavior.
Many real-world programs were not designed with fuzzing in mind. They may:
These patterns make fuzzing difficult because:
The solution is conditional compilation: modify code behavior during fuzzing builds while keeping production code unchanged.
| Concept | Description |
|---|---|
| SUT Patching | Modifying System Under Test to be fuzzing-friendly |
| Conditional Compilation | Code that behaves differently based on compile-time flags |
| Fuzzing Build Mode | Special build configuration that enables fuzzing-specific patches |
| False Positives | Crashes found during fuzzing that cannot occur in production |
| Determinism | Same input always produces same behavior (critical for fuzzing) |
Apply this technique when:
Skip this technique when:
| Task | C/C++ | Rust |
|---|---|---|
| Check if fuzzing build | #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION | cfg!(fuzzing) |
| Skip check during fuzzing | #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION return -1; #endif | if !cfg!(fuzzing) { return Err(...) } |
| Common obstacles | Checksums, PRNGs, time-based logic | Checksums, PRNGs, time-based logic |
| Supported fuzzers | libFuzzer, AFL++, LibAFL, honggfuzz | cargo-fuzz, libFuzzer |
Run the fuzzer and analyze coverage to find code that's unreachable. Common patterns:
rand(), time(), or srand() with system seedsTools to help:
-fprofile-instr-generateModify the obstacle to bypass it during fuzzing builds.
C/C++ Example:
// Before: Hard obstacle
if (checksum != expected_hash) {
return -1; // Fuzzer never gets past here
}
// After: Conditional bypass
if (checksum != expected_hash) {
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
return -1; // Only enforced in production
#endif
}
// Fuzzer can now explore code beyond this checkRust Example:
// Before: Hard obstacle
if checksum != expected_hash {
return Err(MyError::Hash); // Fuzzer never gets past here
}
// After: Conditional bypass
if checksum != expected_hash {
if !cfg!(fuzzing) {
return Err(MyError::Hash); // Only enforced in production
}
}
// Fuzzer can now explore code beyond this checkAfter patching:
Consider whether skipping the check introduces impossible program states:
If false positives are likely, consider a more targeted patch (see Common Patterns below).
Use Case: Hash/checksum blocks all fuzzer progress
Before:
uint32_t computed = hash_function(data, size);
if (computed != expected_checksum) {
return ERROR_INVALID_HASH;
}
process_data(data, size);After:
uint32_t computed = hash_function(data, size);
if (computed != expected_checksum) {
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
return ERROR_INVALID_HASH;
#endif
}
process_data(data, size);False positive risk: LOW - If data processing doesn't depend on checksum correctness
Use Case: Non-deterministic random state prevents reproducibility
Before:
void initialize() {
srand(time(NULL)); // Different seed each run
}After:
void initialize() {
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
srand(12345); // Fixed seed for fuzzing
#else
srand(time(NULL));
#endif
}False positive risk: LOW - Fuzzer can explore all code paths with fixed seed
Use Case: Validation must be skipped but downstream code has assumptions
Before (Dangerous):
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
if (!validate_config(&config)) {
return -1; // Ensures config.x != 0
}
#endif
int32_t result = 100 / config.x; // CRASH: Division by zero in fuzzing!After (Safe):
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
if (!validate_config(&config)) {
return -1;
}
#else
// During fuzzing, use safe defaults for failed validation
if (!validate_config(&config)) {
config.x = 1; // Prevent division by zero
config.y = 1;
}
#endif
int32_t result = 100 / config.x; // Safe in both buildsFalse positive risk: MITIGATED - Provides safe defaults instead of skipping
Use Case: Multi-step validation makes valid input generation nearly impossible
Rust Example:
// Before: Multiple validation stages
pub fn parse_message(data: &[u8]) -> Result<Message, Error> {
validate_magic_bytes(data)?;
validate_structure(data)?;
validate_checksums(data)?;
validate_crypto_signature(data)?;
deserialize_message(data)
}
// After: Skip expensive validation during fuzzing
pub fn parse_message(data: &[u8]) -> Result<Message, Error> {
validate_magic_bytes(data)?; // Keep cheap checks
if !cfg!(fuzzing) {
validate_structure(data)?;
validate_checksums(data)?;
validate_crypto_signature(data)?;
}
deserialize_message(data)
}False positive risk: MEDIUM - Deserialization must handle malformed data gracefully
| Tip | Why It Helps |
|---|---|
| Keep cheap validation | Magic bytes and size checks guide fuzzer without much cost |
| Use fixed seeds for PRNGs | Makes behavior deterministic while exploring all code paths |
| Patch incrementally | Skip one obstacle at a time and measure coverage impact |
| Add defensive defaults | When skipping validation, provide safe fallback values |
| Document all patches | Future maintainers need to understand fuzzing vs. production differences |
OpenSSL: Uses FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION to modify cryptographic algorithm behavior. For example, in crypto/cmp/cmp_vfy.c, certain signature checks are relaxed during fuzzing to allow deeper exploration of certificate validation logic.
ogg crate (Rust): Uses cfg!(fuzzing) to skip checksum verification during fuzzing. This allows the fuzzer to explore audio processing code without spending effort guessing correct checksums.
After applying patches, quantify the improvement:
llvm-cov or cargo-cov to see new reachable linesEffective patches typically increase coverage by 10-50% or more.
Obstacle patching works well with:
| Anti-Pattern | Problem | Correct Approach |
|---|---|---|
| Skip all validation wholesale | Creates false positives and unstable fuzzing | Skip only specific obstacles that block coverage |
| No risk assessment | False positives waste time and hide real bugs | Analyze downstream code for assumptions |
| Forget to document patches | Future maintainers don't understand the differences | Add comments explaining why patch is safe |
| Patch without measuring | Don't know if it helped | Compare coverage before and after |
| Over-patching | Makes fuzzing build diverge too much from production | Minimize differences between builds |
libFuzzer automatically defines FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION during compilation.
# C++ compilation
clang++ -g -fsanitize=fuzzer,address -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION \
harness.cc target.cc -o fuzzer
# The macro is usually defined automatically by -fsanitize=fuzzer
clang++ -g -fsanitize=fuzzer,address harness.cc target.cc -o fuzzerIntegration tips:
#ifdef to check for the macroAFL++ also defines FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION when using its compiler wrappers.
# Compilation with AFL++ wrappers
afl-clang-fast++ -g -fsanitize=address target.cc harness.cc -o fuzzer
# The macro is defined automatically by afl-clang-fastIntegration tips:
afl-clang-fast or afl-clang-lto for automatic macro definitionAFL_LLVM_LAF_ALL for additional input-to-state transformationshonggfuzz also supports the macro when building targets.
# Compilation
hfuzz-clang++ -g -fsanitize=address target.cc harness.cc -o fuzzerIntegration tips:
hfuzz-clang or hfuzz-clang++ wrapperscargo-fuzz automatically sets the fuzzing cfg option during builds.
# Build fuzz target (cfg!(fuzzing) is automatically set)
cargo fuzz build fuzz_target_name
# Run fuzz target
cargo fuzz run fuzz_target_nameIntegration tips:
cfg!(fuzzing) for runtime checks in production builds#[cfg(fuzzing)] for compile-time conditional compilationcargo fuzz builds, not regular cargo buildRUSTFLAGS="--cfg fuzzing" for testingLibAFL supports the C/C++ macro for targets written in C/C++.
# Compilation
clang++ -g -fsanitize=address -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION \
target.cc -c -o target.oIntegration tips:
| Issue | Cause | Solution |
|---|---|---|
| Coverage doesn't improve after patching | Wrong obstacle identified | Profile execution to find actual bottleneck |
| Many false positive crashes | Downstream code has assumptions | Add defensive defaults or partial validation |
| Code compiles differently | Macro not defined in all build configs | Verify macro in all source files and dependencies |
| Fuzzer finds bugs in patched code | Patch introduced invalid states | Review patch for state invariants; consider safer approach |
| Can't reproduce production bugs | Build differences too large | Minimize patches; keep validation for state-critical checks |
| Skill | How It Applies |
|---|---|
| libfuzzer | Defines FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION automatically |
| aflpp | Supports the macro via compiler wrappers |
| honggfuzz | Uses the macro for conditional compilation |
| cargo-fuzz | Sets cfg!(fuzzing) for Rust conditional compilation |
| Skill | Relationship |
|---|---|
| fuzz-harness-writing | Better harnesses may avoid obstacles; patching enables deeper exploration |
| coverage-analysis | Use coverage to identify obstacles and measure patch effectiveness |
| corpus-seeding | Seed corpus can help overcome obstacles without patching |
| dictionary-generation | Dictionaries help with magic bytes but not checksums or complex validation |
OpenSSL Fuzzing Documentation
OpenSSL's fuzzing infrastructure demonstrates large-scale use of FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION. The project uses this macro to modify cryptographic validation, certificate parsing, and other security-critical code paths to enable deeper fuzzing while maintaining production correctness.
LibFuzzer Documentation on Flags Official LLVM documentation for libFuzzer, including how the fuzzer defines compiler macros and how to use them effectively. Covers integration with sanitizers and coverage instrumentation.
Rust cfg Attribute Reference
Complete reference for Rust conditional compilation, including cfg!(fuzzing) and cfg!(test). Explains compile-time vs. runtime conditional compilation and best practices.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/fuzzing-obstacles of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Fuzzing Obstacle Patcher next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fuzzing Obstacle Patcher this skilltrailofbits/skills | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Audit Native Memory Safetycyberful/cyberful | 135 | — | ~829 | Automated safety check: Pass | AGPL-3.0 | |
| Harness Design Fuzzingprovos/ironcurtain | 613 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | |
| ClusterfuzzliteInternationalColorConsortium/iccDEV | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | |
| Fuzzingnwjs/chromium.src | 160 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause | |
| Fuzzingmohitmishra786/low-level-dev-skills | 253 | — | ~2.1k | Automated safety check: Pass | MIT |
cyberful/cyberful
Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
InternationalColorConsortium/iccDEV
Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.
nwjs/chromium.src
Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.
mohitmishra786/low-level-dev-skills
Fuzzing skill for automated input-driven bug finding in C/C++.
mohitmishra786/low-level-dev-skills
Rust security skill for supply chain safety and memory-safe development.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Categories
Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. Programs that verify checksums or hashes, seed random generators from the clock or run heavy validation stop fuzzers from making progress. The skill shows how to locate the blocking check and neutralize it behind a fuzzing build flag using conditional compilation, so the production build keeps its original behavior.
Fuzzing Obstacle Patcher fits situations like: A fuzzer is stuck at checksum or hash verification; coverage shows large regions hidden behind validation; code uses time-based seeds or other non-deterministic global state; valid inputs are impractical to generate by mutation.
Run `npx skills add trailofbits/skills --skill fuzzing-obstacles -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/fuzzing-obstacles in trailofbits/skills) into .claude/skills/fuzzing-obstacles in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill fuzzing-obstacles -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/fuzzing-obstacles in trailofbits/skills) into .agents/skills/fuzzing-obstacles in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill fuzzing-obstacles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzzing-obstacles, .gemini/skills/fuzzing-obstacles, .github/skills/fuzzing-obstacles and .opencode/skills/fuzzing-obstacles in your project.
Going by SKILL.md and its folder, Fuzzing Obstacle Patcher needs the command-line tools its instructions call (cargo).
SKILL.md names 3 domains. As links in the text: github.com, llvm.org and doc.rust-lang.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fuzzing Obstacle Patcher is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fuzzing Obstacle Patcher: Audit Native Memory Safety (cyberful/cyberful, 135 stars), Harness Design Fuzzing (provos/ironcurtain, 613 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars) and Fuzzing (nwjs/chromium.src, 160 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.