Official agent skill

Libafl

by trailofbits in trailofbits/skills

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Libafl

skills CLI
$ npx skills add trailofbits/skills --skill libafl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills libafl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/libafl .claude/skills/libafl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
libafl
GitHub stars
7.4k
Token cost
~4.3k tokens
SKILL.md length
950 words
Files
3 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

  • Works in 2 steps: libFuzzer Drop-in Replacement → Custom Fuzzer as Rust Library
  • Writing a bespoke fuzzer
  • SKILL.md covers When to Use, Quick Start, Installation and Writing a Harness, plus 5 more sections
  • Calls curl, cmake and apt; reaches github.com and raw.githubusercontent.com

What it does

Libafl is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. Covers composing observers, feedbacks, mutators, schedulers, and executors into a fuzzer for targets the standard tools do not fit. Use when writing a bespoke fuzzer or mutator, fuzzing a non-standard target or architecture, implementing a fuzzing research idea, or when libFuzzer and AFL++ lack the control you need.

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including assets (for example `agents/openai.yaml`).

It sits in Security, covering Fuzzing. It works with Rust. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Writing a bespoke fuzzer
  • Fuzzing a non-standard target
  • Implementing a fuzzing research idea
  • LibFuzzer and AFL++ lack the control you need

Example prompts

  • “Use the libafl skill to build custom fuzzers with LibAFL, the modular Rust fuzzing library”
  • “/libafl”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. libFuzzer Drop-in Replacement
  2. Custom Fuzzer as Rust Library

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • cmake
    • apt
    • cargo
    • git
    • wget
    • sh
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • raw.githubusercontent.com
    • apt.llvm.org
    • sh.rustup.rs
    • downloads.sourceforge.net

    Also links to:

    • aflplus.plus
    • docs.rs

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Libafl loads about 4.3k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 950 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:70
    sudo ./llvm.sh 15
  • NotePipes a well-known installer script into a shellSKILL.md:82
    curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 950 words, ~4,286 tokens.

Download SKILL.mdSave it as .claude/skills/libafl/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
libafl
description
Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. Covers composing observers, feedbacks, mutators, schedulers, and executors into a fuzzer for targets the standard tools do not fit. Use when writing a bespoke fuzzer or mutator, fuzzing a non-standard target or architecture, implementing a fuzzing research idea, or when libFuzzer and AFL++ lack the control you need.
type
fuzzer

LibAFL

LibAFL is a modular fuzzing library that implements features from AFL-based fuzzers like AFL++. Unlike traditional fuzzers, LibAFL provides all functionality in a modular and customizable way as a Rust library. It can be used as a drop-in replacement for libFuzzer or as a library to build custom fuzzers from scratch.

When to Use

FuzzerBest ForComplexity
libFuzzerQuick setup, single-threadedLow
AFL++Multi-core, general purposeMedium
LibAFLCustom fuzzers, advanced features, researchHigh

Choose LibAFL when:

  • You need custom mutation strategies or feedback mechanisms
  • Standard fuzzers don't support your target architecture
  • You want to implement novel fuzzing techniques
  • You need fine-grained control over fuzzing components
  • You're conducting fuzzing research

Quick Start

LibAFL can be used as a drop-in replacement for libFuzzer with minimal setup:

c++
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
    // Call your code with fuzzer-provided data
    my_function(data, size);
    return 0;
}

Build LibAFL's libFuzzer compatibility layer:

bash
git clone https://github.com/AFLplusplus/LibAFL
cd LibAFL/libafl_libfuzzer_runtime
./build.sh

Compile and run:

bash
clang++ -DNO_MAIN -g -O2 -fsanitize=fuzzer-no-link libFuzzer.a harness.cc main.cc -o fuzz
./fuzz corpus/

Installation

Prerequisites
  • Clang/LLVM 15-18
  • Rust (via rustup)
  • Additional system dependencies
Linux/macOS

Install Clang:

bash
apt install clang

Or install a specific version via apt.llvm.org:

bash
wget https://apt.llvm.org/llvm.sh
chmod +x llvm.sh
sudo ./llvm.sh 15

Configure environment for Rust:

bash
export RUSTFLAGS="-C linker=/usr/bin/clang-15"
export CC="clang-15"
export CXX="clang++-15"

Install Rust:

bash
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Install additional dependencies:

bash
apt install libssl-dev pkg-config

For libFuzzer compatibility mode, install nightly Rust:

bash
rustup toolchain install nightly --component llvm-tools
Verification

Build LibAFL to verify installation:

bash
cd LibAFL/libafl_libfuzzer_runtime
./build.sh
# Should produce libFuzzer.a

Writing a Harness

LibAFL harnesses follow the same pattern as libFuzzer when using drop-in replacement mode:

c++
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
    // Your fuzzing target code here
    return 0;
}

When building custom fuzzers with LibAFL as a Rust library, harness logic is integrated directly into the fuzzer. See the "Writing a Custom Fuzzer" section below for the full pattern.

See Also: For detailed harness writing techniques, see the harness-writing technique skill.

Usage Modes

LibAFL supports two primary usage modes:

1. libFuzzer Drop-in Replacement

Use LibAFL as a replacement for libFuzzer with existing harnesses.

Compilation:

bash
clang++ -DNO_MAIN -g -O2 -fsanitize=fuzzer-no-link libFuzzer.a harness.cc main.cc -o fuzz

Running:

bash
./fuzz corpus/

Recommended for long campaigns:

bash
./fuzz -fork=1 -ignore_crashes=1 corpus/
2. Custom Fuzzer as Rust Library

Build a fully customized fuzzer using LibAFL components.

Create project:

bash
cargo init --lib my_fuzzer
cd my_fuzzer
cargo add libafl@0.13 libafl_targets@0.13 libafl_bolts@0.13 libafl_cc@0.13 \
  --features "libafl_targets@0.13/libfuzzer,libafl_targets@0.13/sancov_pcguard_hitcounts"

Configure Cargo.toml:

toml
[lib]
crate-type = ["staticlib"]

Writing a Custom Fuzzer

See Also: For detailed harness writing techniques, patterns for handling complex inputs, and advanced strategies, see the fuzz-harness-writing technique skill.

Fuzzer Components

A LibAFL fuzzer consists of modular components:

  1. Observers - Collect execution feedback (coverage, timing)
  2. Feedback - Determine if inputs are interesting
  3. Objective - Define fuzzing goals (crashes, timeouts)
  4. State - Maintain corpus and metadata
  5. Mutators - Generate new inputs
  6. Scheduler - Select which inputs to mutate
  7. Executor - Run the target with inputs
Basic Fuzzer Structure
rust
use libafl::prelude::*;
use libafl_bolts::prelude::*;
use libafl_targets::{libfuzzer_test_one_input, std_edges_map_observer};

#[no_mangle]
pub extern "C" fn libafl_main() {
    let mut run_client = |state: Option<_>, mut restarting_mgr, _core_id| {
        // 1. Setup observers
        let edges_observer = HitcountsMapObserver::new(
            unsafe { std_edges_map_observer("edges") }
        ).track_indices();
        let time_observer = TimeObserver::new("time");

        // 2. Define feedback
        let mut feedback = feedback_or!(
            MaxMapFeedback::new(&edges_observer),
            TimeFeedback::new(&time_observer)
        );

        // 3. Define objective
        let mut objective = feedback_or_fast!(
            CrashFeedback::new(),
            TimeoutFeedback::new()
        );

        // 4. Create or restore state
        let mut state = state.unwrap_or_else(|| {
            StdState::new(
                StdRand::new(),
                InMemoryCorpus::new(),
                OnDiskCorpus::new(&output_dir).unwrap(),
                &mut feedback,
                &mut objective,
            ).unwrap()
        });

        // 5. Setup mutator
        let mutator = StdScheduledMutator::new(havoc_mutations());
        let mut stages = tuple_list!(StdMutationalStage::new(mutator));

        // 6. Setup scheduler
        let scheduler = IndexesLenTimeMinimizerScheduler::new(
            &edges_observer,
            QueueScheduler::new()
        );

        // 7. Create fuzzer
        let mut fuzzer = StdFuzzer::new(scheduler, feedback, objective);

        // 8. Define harness
        let mut harness = |input: &BytesInput| {
            let buf = input.target_bytes().as_slice();
            libfuzzer_test_one_input(buf);
            ExitKind::Ok
        };

        // 9. Setup executor
        let mut executor = InProcessExecutor::with_timeout(
            &mut harness,
            tuple_list!(edges_observer, time_observer),
            &mut fuzzer,
            &mut state,
            &mut restarting_mgr,
            timeout,
        )?;

        // 10. Load initial inputs
        if state.must_load_initial_inputs() {
            state.load_initial_inputs(
                &mut fuzzer,
                &mut executor,
                &mut restarting_mgr,
                &input_dir
            )?;
        }

        // 11. Start fuzzing
        fuzzer.fuzz_loop(&mut stages, &mut executor, &mut state, &mut restarting_mgr)?;
        Ok(())
    };

    // Launch fuzzer
    Launcher::builder()
        .run_client(&mut run_client)
        .cores(&cores)
        .build()
        .launch()
        .unwrap();
}

Compilation

Verbose Mode

Manually specify all instrumentation flags:

bash
clang++-15 -DNO_MAIN -g -O2 \
  -fsanitize-coverage=trace-pc-guard \
  -fsanitize=address \
  -Wl,--whole-archive target/release/libmy_fuzzer.a -Wl,--no-whole-archive \
  main.cc harness.cc -o fuzz

Create a LibAFL compiler wrapper to handle instrumentation automatically.

Create src/bin/libafl_cc.rs:

rust
use libafl_cc::{ClangWrapper, CompilerWrapper, Configuration, ToolWrapper};

pub fn main() {
    let args: Vec<String> = env::args().collect();
    let mut cc = ClangWrapper::new();
    cc.cpp(is_cpp)
      .parse_args(&args)
      .link_staticlib(&dir, "my_fuzzer")
      .add_args(&Configuration::GenerateCoverageMap.to_flags().unwrap())
      .add_args(&Configuration::AddressSanitizer.to_flags().unwrap())
      .run()
      .unwrap();
}

Compile and use:

bash
cargo build --release
target/release/libafl_cxx -DNO_MAIN -g -O2 main.cc harness.cc -o fuzz

See Also: For detailed sanitizer configuration, common issues, and advanced flags, see the address-sanitizer and undefined-behavior-sanitizer technique skills.

Running Campaigns

Basic Run
bash
./fuzz --cores 0 --input corpus/
Multi-Core Fuzzing
bash
./fuzz --cores 0,8-15 --input corpus/

This runs 9 clients: one on core 0, and 8 on cores 8-15.

With Options
bash
./fuzz --cores 0-7 --input corpus/ --output crashes/ --timeout 1000
Text User Interface (TUI)

Enable graphical statistics view:

bash
./fuzz -tui=1 corpus/
Interpreting Output
OutputMeaning
corpus: NNumber of interesting test cases found
objectives: NNumber of crashes/timeouts found
executions: NTotal number of target invocations
exec/sec: NCurrent execution throughput
edges: X%Code coverage percentage
clients: NNumber of parallel fuzzing processes

The fuzzer emits two main event types:

  • UserStats - Regular heartbeat with current statistics
  • Testcase - New interesting input discovered

Advanced Usage

Tips and Tricks
TipWhy It Helps
Use -fork=1 -ignore_crashes=1Continue fuzzing after first crash
Use InMemoryOnDiskCorpusPersist corpus across restarts
Enable TUI with -tui=1Better visualization of progress
Use specific LLVM versionAvoid compatibility issues
Set RUSTFLAGS correctlyPrevent linking errors
Crash Deduplication

Avoid storing duplicate crashes from the same bug:

Add backtrace observer:

rust
let backtrace_observer = BacktraceObserver::owned(
    "BacktraceObserver",
    libafl::observers::HarnessType::InProcess
);

Update executor:

rust
let mut executor = InProcessExecutor::with_timeout(
    &mut harness,
    tuple_list!(edges_observer, time_observer, backtrace_observer),
    &mut fuzzer,
    &mut state,
    &mut restarting_mgr,
    timeout,
)?;

Update objective with hash feedback:

rust
let mut objective = feedback_and!(
    feedback_or_fast!(CrashFeedback::new(), TimeoutFeedback::new()),
    NewHashFeedback::new(&backtrace_observer)
);

This ensures only crashes with unique backtraces are saved.

Show full SKILL.md (382 more words)Show less
Dictionary Fuzzing

Use dictionaries to guide fuzzing toward specific tokens:

Add tokens from file:

rust
let mut tokens = Tokens::new();
if let Some(tokenfile) = &tokenfile {
    tokens.add_from_file(tokenfile)?;
}
state.add_metadata(tokens);

Update mutator:

rust
let mutator = StdScheduledMutator::new(
    havoc_mutations().merge(tokens_mutations())
);

Hard-coded tokens example (PNG):

rust
state.add_metadata(Tokens::from([
    vec![137, 80, 78, 71, 13, 10, 26, 10], // PNG header
    "IHDR".as_bytes().to_vec(),
    "IDAT".as_bytes().to_vec(),
    "PLTE".as_bytes().to_vec(),
    "IEND".as_bytes().to_vec(),
]));

See Also: For detailed dictionary creation strategies and format-specific dictionaries, see the fuzzing-dictionaries technique skill.

Auto Tokens

Automatically extract magic values and checksums from the program:

Enable in compiler wrapper:

rust
cc.add_pass(LLVMPasses::AutoTokens)

Load auto tokens in fuzzer:

rust
tokens += libafl_targets::autotokens()?;

Verify tokens section:

bash
echo "p (uint8_t *)__token_start" | gdb fuzz
Performance Tuning
SettingImpact
Multi-core fuzzingLinear speedup with cores
InMemoryCorpusFaster but non-persistent
InMemoryOnDiskCorpusBalanced speed and persistence
Sanitizers2-5x slowdown, essential for bugs
Optimization level -O2Balance between speed and coverage
Debugging Fuzzer

Run fuzzer in single-process mode for easier debugging:

rust
// Replace launcher with direct call
run_client(None, SimpleEventManager::new(monitor), 0).unwrap();

// Comment out:
// Launcher::builder()
//     .run_client(&mut run_client)
//     ...
//     .launch()

Then debug with GDB:

bash
gdb --args ./fuzz --cores 0 --input corpus/

Real-World Examples

Example: libpng

Fuzzing libpng using LibAFL:

1. Get source code:

bash
curl -L -O https://downloads.sourceforge.net/project/libpng/libpng16/1.6.37/libpng-1.6.37.tar.xz
tar xf libpng-1.6.37.tar.xz
cd libpng-1.6.37/
apt install zlib1g-dev

2. Set compiler wrapper:

bash
export FUZZER_CARGO_DIR="/path/to/libafl/project"
export CC=$FUZZER_CARGO_DIR/target/release/libafl_cc
export CXX=$FUZZER_CARGO_DIR/target/release/libafl_cxx

3. Build static library:

bash
./configure --enable-shared=no
make

4. Get harness:

bash
curl -O https://raw.githubusercontent.com/glennrp/libpng/f8e5fa92b0e37ab597616f554bee254157998227/contrib/oss-fuzz/libpng_read_fuzzer.cc

5. Link fuzzer:

bash
$CXX libpng_read_fuzzer.cc .libs/libpng16.a -lz -o fuzz

6. Prepare seeds:

bash
mkdir seeds/
curl -o seeds/input.png https://raw.githubusercontent.com/glennrp/libpng/acfd50ae0ba3198ad734e5d4dec2b05341e50924/contrib/pngsuite/iftp1n3p08.png

7. Get dictionary (optional):

bash
curl -O https://raw.githubusercontent.com/glennrp/libpng/2fff013a6935967960a5ae626fc21432807933dd/contrib/oss-fuzz/png.dict

8. Start fuzzing:

bash
./fuzz --input seeds/ --cores 0 -x png.dict
Example: CMake Project

Integrate LibAFL with CMake build system:

CMakeLists.txt:

cmake
project(BuggyProgram)
cmake_minimum_required(VERSION 3.0)

add_executable(buggy_program main.cc)

add_executable(fuzz main.cc harness.cc)
target_compile_definitions(fuzz PRIVATE NO_MAIN=1)
target_compile_options(fuzz PRIVATE -g -O2)

Build non-instrumented binary:

bash
cmake -DCMAKE_C_COMPILER=clang -DCMAKE_CXX_COMPILER=clang++ .
cmake --build . --target buggy_program

Build fuzzer:

bash
export FUZZER_CARGO_DIR="/path/to/libafl/project"
cmake -DCMAKE_C_COMPILER=$FUZZER_CARGO_DIR/target/release/libafl_cc \
      -DCMAKE_CXX_COMPILER=$FUZZER_CARGO_DIR/target/release/libafl_cxx .
cmake --build . --target fuzz

Run fuzzing:

bash
./fuzz --input seeds/ --cores 0

Troubleshooting

ProblemCauseSolution
No coverage increasesInstrumentation failedVerify compiler wrapper used, check for -fsanitize-coverage
Fuzzer won't startEmpty corpus with no interesting inputsProvide seed inputs that trigger code paths
Linker errors with libafl_mainRuntime not linkedUse -Wl,--whole-archive or -u libafl_main
LLVM version mismatchLibAFL requires LLVM 15-18Install compatible LLVM version, set environment variables
Rust compilation failsOutdated Rust or CargoUpdate Rust with rustup update
Slow fuzzingSanitizers enabledExpected 2-5x slowdown, necessary for finding bugs
Environment variable interferenceCC, CXX, RUSTFLAGS setUnset after building LibAFL project
Cannot attach debuggerMulti-process fuzzingRun in single-process mode (see Debugging section)
Technique Skills
SkillUse Case
fuzz-harness-writingDetailed guidance on writing effective harnesses
address-sanitizerMemory error detection during fuzzing
undefined-behavior-sanitizerUndefined behavior detection
coverage-analysisMeasuring and improving code coverage
fuzzing-corpusBuilding and managing seed corpora
fuzzing-dictionariesCreating dictionaries for format-aware fuzzing
SkillWhen to Consider
libfuzzerSimpler setup, don't need LibAFL's advanced features
aflppMulti-core fuzzing without custom fuzzer development
cargo-fuzzFuzzing Rust projects with less setup

Resources

Official Documentation
Examples and Tutorials

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/libafl of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Libafl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Libafl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Libafl this skilltrailofbits/skills7.4k—~4.3kAutomated safety check: NotesCC-BY-SA-4.0
Audit Native Memory Safetycyberful/cyberful134—~829Automated safety check: PassAGPL-3.0
Rust Securitymohitmishra786/low-level-dev-skills253—~1.6kAutomated safety check: PassMIT
Solana Audit Flowmtarcure/claude-vibe-squad162—~1.4kAutomated safety check: PassMIT
GreptimeDB Fuzz CI Failure InvestigationGreptimeTeam/greptimedb6.7k—~4.4kAutomated safety check: PassApache-2.0
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT

Similar skills

  • Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

    134 GitHub stars~829 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Rust Security

    mohitmishra786/low-level-dev-skills

    Rust security skill for supply chain safety and memory-safe development.

    253 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Solana Audit Flow

    mtarcure/claude-vibe-squad

    A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…

    162 GitHub stars~1.4k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code.

    6.7k GitHub stars~4.4k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Libafl

What does Libafl do?

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. Libafl is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

When should I use Libafl?

Libafl fits situations like: writing a bespoke fuzzer; fuzzing a non-standard target; implementing a fuzzing research idea; libFuzzer and AFL++ lack the control you need.

How do I install Libafl in Claude Code?

Run `npx skills add trailofbits/skills --skill libafl -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/libafl in trailofbits/skills) into .claude/skills/libafl in your project. Claude Code loads it when a task matches its description.

How do I install Libafl in Codex?

Run `npx skills add trailofbits/skills --skill libafl -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/libafl in trailofbits/skills) into .agents/skills/libafl in your project. Codex loads it when a task matches its description.

Can I use Libafl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill libafl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/libafl, .gemini/skills/libafl, .github/skills/libafl and .opencode/skills/libafl in your project.

What does Libafl need to run?

Going by SKILL.md and its folder, Libafl needs the command-line tools its instructions call (curl, cmake, apt, cargo, git and wget).

Does Libafl access the network?

SKILL.md names 7 domains. In commands or code: github.com, raw.githubusercontent.com, apt.llvm.org, sh.rustup.rs and downloads.sourceforge.net; the agent is likely to contact these when it follows the instructions. As links in the text: aflplus.plus and docs.rs. This is read from the text; nothing was executed.

Is Libafl safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo; pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Libafl use?

Libafl is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Libafl use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Libafl?

Skills that share tags, products or a category with Libafl: Audit Native Memory Safety (cyberful/cyberful, 134 stars), Rust Security (mohitmishra786/low-level-dev-skills, 253 stars), Solana Audit Flow (mtarcure/claude-vibe-squad, 162 stars) and GreptimeDB Fuzz CI Failure Investigation (GreptimeTeam/greptimedb, 6.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Libafl?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.