DeerFlow Smoke Test
bytedance/deer-flow
Walks through an end-to-end smoke test of a DeerFlow deployment: pull the latest code, deploy with Docker or locally, verify services, run health checks and write a report.
Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.
$ npx skills add trailofbits/skills --skill ossfuzz -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills ossfuzz --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .claude/skills/ossfuzz && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .claude/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzzType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill ossfuzz -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills ossfuzz --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .agents/skills/ossfuzz && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .agents/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill ossfuzz -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills ossfuzz --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .cursor/skills/ossfuzz && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .cursor/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/testing-handbook-skills/skills/ossfuzz--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill ossfuzz -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills ossfuzz --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .gemini/skills/ossfuzz && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .gemini/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills ossfuzzInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill ossfuzz -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .github/skills/ossfuzz && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .github/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill ossfuzz -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills ossfuzz --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/testing-handbook-skills/skills/ossfuzz .opencode/skills/ossfuzz && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ossfuzz" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/testing-handbook-skills/skills/ossfuzz into .opencode/skills/ossfuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ossfuzz", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ossfuzzEnrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.
Ossfuzz is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. Covers project.yaml, Dockerfile and build.sh setup, the helper scripts, reproducing OSS-Fuzz crash reports, and the acceptance criteria. Use when setting up continuous fuzzing for an open-source project, reproducing an OSS-Fuzz bug report, or testing an OSS-Fuzz build before submitting it.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including assets (for example `agents/openai.yaml`).
It sits in Security, covering Fuzzing, Containers and QA and bug reports. It works with Docker. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvgitmakepip3cargoapt-getFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
google.github.ioissues.oss-fuzz.comoss-fuzz-build-logs.storage.googleapis.comoss-fuzz-introspector.storage.googleapis.comappsec.guidecloud.google.comblog.trailofbits.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ossfuzz loads about 4.2k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,232 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,232 words, ~4,185 tokens.
.claude/skills/ossfuzz/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.OSS-Fuzz is an open-source project developed by Google that provides free distributed infrastructure for continuous fuzz testing. It streamlines the fuzzing process and facilitates simpler modifications. While only select projects are accepted into OSS-Fuzz, the project's core is open-source, allowing anyone to host their own instance for private projects.
OSS-Fuzz provides a simple CLI framework for building and starting harnesses or calculating their coverage. Additionally, OSS-Fuzz can be used as a service that hosts static web pages generated from fuzzing outputs such as coverage information.
| Concept | Description |
|---|---|
| helper.py | CLI script for building images, building fuzzers, and running harnesses locally |
| Base Images | Hierarchical Docker images providing build dependencies and compilers |
| project.yaml | Configuration file defining project metadata for OSS-Fuzz enrollment |
| Dockerfile | Project-specific image with build dependencies |
| build.sh | Script that builds fuzzing harnesses for your project |
| Criticality Score | Metric used by OSS-Fuzz team to evaluate project acceptance |
Apply this technique when:
Skip this technique when:
| Task | Command |
|---|---|
| Clone OSS-Fuzz | git clone https://github.com/google/oss-fuzz |
| Build project image | uv run --no-project python infra/helper.py build_image --pull <project> |
| Build fuzzers with ASan | uv run --no-project python infra/helper.py build_fuzzers --sanitizer=address <project> |
| Run specific harness | uv run --no-project python infra/helper.py run_fuzzer <project> <harness> |
| Generate coverage report | uv run --no-project python infra/helper.py coverage <project> |
| Check helper.py options | uv run --no-project python infra/helper.py --help |
OSS-Fuzz provides several publicly available tools and web interfaces:
The bug tracker allows you to:
The build status system helps track:
Fuzz Introspector displays:
Read this case study for examples and explanations.
You don't need to host the whole OSS-Fuzz platform to use it. The helper script makes it easy to run individual harnesses locally.
git clone https://github.com/google/oss-fuzz
cd oss-fuzz
uv run --no-project python infra/helper.py --helpuv run --no-project python infra/helper.py build_image --pull <project-name>This downloads and builds the base Docker image for the project.
uv run --no-project python infra/helper.py build_fuzzers --sanitizer=address <project-name>Sanitizer options:
--sanitizer=address for AddressSanitizer with LeakSanitizerNote: Fuzzers are built to /build/out/<project-name>/ containing the harness executables, dictionaries, corpus, and crash files.
uv run --no-project python infra/helper.py run_fuzzer <project-name> <harness-name> [<fuzzer-args>]The helper script automatically runs any missed steps if you skip them.
First, install gsutil (skip gcloud initialization).
uv run --no-project python infra/helper.py build_fuzzers --sanitizer=coverage <project-name>
uv run --no-project python infra/helper.py coverage <project-name>Use --no-corpus-download to use only local corpus. The command generates and hosts a coverage report locally.
See official OSS-Fuzz documentation for details.
Use Case: Testing OSS-Fuzz setup with a simple enrolled project
# Clone and navigate to OSS-Fuzz
git clone https://github.com/google/oss-fuzz
cd oss-fuzz
# Build and run irssi fuzzer
uv run --no-project python infra/helper.py build_image --pull irssi
uv run --no-project python infra/helper.py build_fuzzers --sanitizer=address irssi
uv run --no-project python infra/helper.py run_fuzzer irssi irssi-fuzzExpected Output:
INFO:__main__:Running: docker run --rm --privileged --shm-size=2g --platform linux/amd64 -i -e FUZZING_ENGINE=libfuzzer -e SANITIZER=address -e RUN_FUZZER_MODE=interactive -e HELPER=True -v /private/tmp/oss-fuzz/build/out/irssi:/out -t gcr.io/oss-fuzz-base/base-runner run_fuzzer irssi-fuzz.
Using seed corpus: irssi-fuzz_seed_corpus.zip
/out/irssi-fuzz -rss_limit_mb=2560 -timeout=25 /tmp/irssi-fuzz_corpus -max_len=2048 < /dev/null
INFO: Running with entropic power schedule (0xFF, 100).
INFO: Seed: 1531341664
INFO: Loaded 1 modules (95687 inline 8-bit counters): 95687 [0x1096c80, 0x10ae247),
INFO: Loaded 1 PC tables (95687 PCs): 95687 [0x10ae248,0x1223eb8),
INFO: 719 files found in /tmp/irssi-fuzz_corpus
INFO: seed corpus: files: 719 min: 1b max: 170106b total: 367969b rss: 48Mb
#720 INITED cov: 409 ft: 1738 corp: 640/163Kb exec/s: 0 rss: 62Mb
#762 REDUCE cov: 409 ft: 1738 corp: 640/163Kb lim: 2048 exec/s: 0 rss: 63Mb L: 236/2048 MS: 2 ShuffleBytes-EraseBytes-Use Case: Adding your project to OSS-Fuzz (or private instance)
Create three files in projects/<your-project>/:
1. project.yaml - Project metadata:
homepage: "https://github.com/yourorg/yourproject"
language: c++
primary_contact: "your-email@example.com"
main_repo: "https://github.com/yourorg/yourproject"
fuzzing_engines:
- libfuzzer
sanitizers:
- address
- undefined2. Dockerfile - Build dependencies:
FROM gcr.io/oss-fuzz-base/base-builder
RUN apt-get update && apt-get install -y \
autoconf \
automake \
libtool \
pkg-config
RUN git clone --depth 1 https://github.com/yourorg/yourproject
WORKDIR yourproject
COPY build.sh $SRC/3. build.sh - Build harnesses:
#!/bin/bash -eu
./autogen.sh
./configure --disable-shared
make -j$(nproc)
# Build harnesses
$CXX $CXXFLAGS -std=c++11 -I. \
$SRC/yourproject/fuzz/harness.cc -o $OUT/harness \
$LIB_FUZZING_ENGINE ./libyourproject.a
# Copy corpus and dictionary if available
cp $SRC/yourproject/fuzz/corpus.zip $OUT/harness_seed_corpus.zip
cp $SRC/yourproject/fuzz/dictionary.dict $OUT/harness.dictHarnesses are built and executed in Docker containers. All projects share a runner image, but each project has its own build image.
Images build on each other in this sequence:
base_imagebase_clangbase_builder_go, etc.base_builder or language variantbase_clangbase_runner| Tip | Why It Helps |
|---|---|
| Don't manually copy source code | Project Dockerfile likely already pulls latest version |
| Check existing projects | Browse oss-fuzz/projects for examples |
| Keep harnesses in separate repo | Like curl-fuzzer - cleaner organization |
| Use specific compiler versions | Base images provide consistent build environment |
| Install dependencies in Dockerfile | May require approval for OSS-Fuzz enrollment |
OSS-Fuzz uses a criticality score to evaluate project acceptance. See this example for how scoring works.
Projects with lower scores may still be added to private OSS-Fuzz instances.
Since OSS-Fuzz is open-source, you can host your own instance for:
| Anti-Pattern | Problem | Correct Approach |
|---|---|---|
| Manually pulling source in build.sh | Doesn't use latest version | Let Dockerfile handle git clone |
| Copying code to OSS-Fuzz repo | Hard to maintain, violates separation | Reference external harness repo |
| Ignoring base image versions | Build inconsistencies | Use provided base images and compilers |
| Skipping local testing | Wastes CI resources | Use helper.py locally before PR |
| Not checking build status | Unnoticed build failures | Monitor build status page regularly |
OSS-Fuzz primarily uses libFuzzer as the fuzzing engine for C/C++ projects.
Harness signature:
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
// Your fuzzing logic
return 0;
}Build in build.sh:
$CXX $CXXFLAGS -std=c++11 -I. \
harness.cc -o $OUT/harness \
$LIB_FUZZING_ENGINE ./libproject.aIntegration tips:
$LIB_FUZZING_ENGINE variable provided by OSS-Fuzz-fsanitize=fuzzer is handled automaticallyOSS-Fuzz supports AFL++ as an alternative fuzzing engine.
Enable in project.yaml:
fuzzing_engines:
- afl
- libfuzzerIntegration tips:
For Python projects with C extensions.
Example from cbor2 integration:
Harness:
import atheris
import sys
import cbor2
@atheris.instrument_func
def TestOneInput(data):
fdp = atheris.FuzzedDataProvider(data)
try:
cbor2.loads(data)
except (cbor2.CBORDecodeError, ValueError):
pass
def main():
atheris.Setup(sys.argv, TestOneInput)
atheris.Fuzz()
if __name__ == "__main__":
main()Build in build.sh:
# allow-legacy-python: build.sh runs inside the oss-fuzz container, where the shims are absent.
pip3 install .
for fuzzer in $(find $SRC -name 'fuzz_*.py'); do
compile_python_fuzzer $fuzzer
doneIntegration tips:
compile_python_fuzzer helper provided by OSS-FuzzEnable in project.yaml:
language: rust
fuzzing_engines:
- libfuzzer
sanitizers:
- address # Only AddressSanitizer supported for RustBuild in build.sh:
cargo fuzz build -O --debug-assertions
cp fuzz/target/x86_64-unknown-linux-gnu/release/fuzz_target_1 $OUT/Integration tips:
| Issue | Cause | Solution |
|---|---|---|
| Build fails with missing dependencies | Dependencies not in Dockerfile | Add apt-get install or equivalent in Dockerfile |
| Harness crashes immediately | Missing input validation | Add size checks in harness |
| Coverage is 0% | Harness not reaching target code | Verify harness actually calls target functions |
| Build timeout | Complex build process | Optimize build.sh, consider parallel builds |
| Sanitizer errors in build | Incompatible flags | Use flags provided by OSS-Fuzz environment variables |
| Cannot find source code | Wrong working directory in Dockerfile | Set WORKDIR or use absolute paths |
| Skill | How It Applies |
|---|---|
| libfuzzer | Primary fuzzing engine used by OSS-Fuzz |
| aflpp | Alternative fuzzing engine supported by OSS-Fuzz |
| atheris | Used for fuzzing Python projects in OSS-Fuzz |
| cargo-fuzz | Used for Rust projects in OSS-Fuzz |
| Skill | Relationship |
|---|---|
| coverage-analysis | OSS-Fuzz generates coverage reports via helper.py |
| address-sanitizer | Default sanitizer for OSS-Fuzz projects |
| fuzz-harness-writing | Essential for enrolling projects in OSS-Fuzz |
| corpus-management | OSS-Fuzz maintains corpus for enrolled projects |
OSS-Fuzz Official Documentation Comprehensive documentation covering enrollment, harness writing, and troubleshooting for the OSS-Fuzz platform.
Getting Started Guide Step-by-step process for enrolling new projects into OSS-Fuzz, including requirements and approval process.
cbor2 OSS-Fuzz Integration PR Real-world example of enrolling a Python project with C extensions into OSS-Fuzz. Shows:
Fuzz Introspector Case Studies Examples and explanations of using Fuzz Introspector to analyze coverage and identify fuzzing blockers.
Check OSS-Fuzz documentation for workshop recordings and tutorials on enrollment and harness development.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (assets) in plugins/testing-handbook-skills/skills/ossfuzz of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Ossfuzz next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ossfuzz this skilltrailofbits/skills | 7.4k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| DeerFlow Smoke Testbytedance/deer-flow | 83k | — | ~2.5k | Automated safety check: Notes | MIT | |
| PgjevrealZachi/pg-jev | 1k | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Onboarding Validationopen-edge-platform/edge-ai-suites | 140 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Lineth QuickstartLFDT-Lineth/lineth-monorepo | 126 | — | ~1k | Automated safety check: Notes | AGPL-3.0 | |
| Lvc Run Appopen-edge-platform/edge-ai-suites | 140 | — | ~796 | Automated safety check: Pass | Apache-2.0 |
bytedance/deer-flow
Walks through an end-to-end smoke test of a DeerFlow deployment: pull the latest code, deploy with Docker or locally, verify services, run health checks and write a report.
realZachi/pg-jev
Install, configure, query and explain pgjev (the jev PostgreSQL extension that filters, ranks and classifies rows with plain-language conditions via TypeSafe's Jev model).
open-edge-platform/edge-ai-suites
Validate the get-started experience of Open Edge Platform (OEP) software components from the perspective of a first-time user.
LFDT-Lineth/lineth-monorepo
Operating manual for the Lineth Stack quickstart — the Docker-Compose dev/demo stack at docs/getting-started/lineth-stack in the lineth-monorepo that boots a local Linea/Lineth L2 with Sepolia or…
open-edge-platform/edge-ai-suites
Run, start, or smoke-test the Live Video Captioning app (Docker Compose stack with dashboard on :4173).
Elite588/AUTOGPT
E2E manual testing of PRs/branches using docker compose, agent-browser, and API calls.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
Works with
Categories
Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. Ossfuzz is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.
Ossfuzz fits situations like: setting up continuous fuzzing for an open-source project; reproducing an OSS-Fuzz bug report; testing an OSS-Fuzz build before submitting it.
Run `npx skills add trailofbits/skills --skill ossfuzz -a claude-code`. Or copy the skill folder (plugins/testing-handbook-skills/skills/ossfuzz in trailofbits/skills) into .claude/skills/ossfuzz in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill ossfuzz -a codex`. Or copy the skill folder (plugins/testing-handbook-skills/skills/ossfuzz in trailofbits/skills) into .agents/skills/ossfuzz in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill ossfuzz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ossfuzz, .gemini/skills/ossfuzz, .github/skills/ossfuzz and .opencode/skills/ossfuzz in your project.
Going by SKILL.md and its folder, Ossfuzz needs the command-line tools its instructions call (uv, git, make, pip3, cargo and apt-get). Our summary lists: Python 3; Docker.
SKILL.md names 8 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: google.github.io, issues.oss-fuzz.com, oss-fuzz-build-logs.storage.googleapis.com, oss-fuzz-introspector.storage.googleapis.com, appsec.guide, cloud.google.com and blog.trailofbits.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ossfuzz is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ossfuzz: DeerFlow Smoke Test (bytedance/deer-flow, 83k stars), Pgjev (realZachi/pg-jev, 1k stars), Onboarding Validation (open-edge-platform/edge-ai-suites, 140 stars) and Lineth Quickstart (LFDT-Lineth/lineth-monorepo, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.