Topic · Security

Best fuzzing skills for Claude Code, Codex and other agents.

Skills that build fuzz harnesses and triage crashes.
skills
75
official
13

Fuzzing skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Fuzzing skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

pashov/skills1.2k2 repos~11kAutomated safety check: PassMIT2 days ago
2

Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code.

GreptimeTeam/greptimedb6.7k—~4.4kAutomated safety check: PassApache-2.02 days ago
3

Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

digoal/blog8.6k—~4kAutomated safety check: PassGPL-2.09 days ago
4

Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage.

antoniopaya22/go-rest-template1729 repos~4.2kAutomated safety check: PassNo licence6 mo ago
5

Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

pashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT2 days ago
6

Reconcile an existing Fizz harness with a changed source tree.

pashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT2 days ago
7

Treat an open-ended investigation the way a fuzzer treats a program.

ARA-Labs/Agent-Native-Research-Artifact690—~2.4kAutomated safety check: PassMITtoday
8

Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims.

inkline/inkline1.5k—~1.2kAutomated safety check: PassNo licence26 days ago
9

安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

tanweai/xianzhi-research185—~847Automated safety check: PassNo licence8 mo ago
10

Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

tihanyin/REx-skill105—~5.1kAutomated safety check: PassMIT14 days ago
11

Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

Encod3d-Sec/TORCH3291 repo~1.3kAutomated safety check: PassMIT1 mo ago
12

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

jabrena/plinth445—~874Automated safety check: PassApache-2.0today
13

Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

provos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0today
14

Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

opensage-agent/opensage-adk127—~542Automated safety check: PassApache-2.02 mo ago
15

Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security.

aviggiano/security144—~584Automated safety check: PassMIT21 days ago
16

Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup.

tradecatlabs/vibe-coding-cn17k2 repos~9.9kAutomated safety check: PassMIT6 days ago
17

Adds a new Go fuzz target to remindb following its seed-corpus discipline: one target per logical surface, discovered automatically by its FuzzXxx function name.

radimsem/remindb129—~1.7kAutomated safety check: PassMIT2 mo ago
18

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

InternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clausetoday
19

Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.

s3s-project/s3s311—~838Automated safety check: PassApache-2.0today
20

Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

cyberful/cyberful134—~1.5kAutomated safety check: PassAGPL-3.01 mo ago
21

Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

aviggiano/security144—~2.8kAutomated safety check: PassMIT21 days ago
22

Production-ready Golang tests — table-driven tests, testify suites and mocks, parallel tests, fuzzing, fixtures, goroutine leak detection with goleak, snapshot testing, code coverage, integration…

unxed/f42401 repo~4.5kAutomated safety check: PassMITtoday
23

Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

aftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.04 days ago
24

Extract crash inputs from fuzzing output into a target directory.

opensage-agent/opensage-adk127—~215Automated safety check: PassApache-2.02 mo ago
25

Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

trailofbits/skills7.4k1 repo~5.3kAutomated safety check: PassCC-BY-SA-4.05 days ago
26

Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

Gabson0x/bountyforge443—~1.6kAutomated safety check: PassNo licence20 days ago
27

Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

AgentSecOps/SecOpsAgentKit2191 repo~3.3kAutomated safety check: PassUnknown5 mo ago
28

Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets.

trailofbits/skills7.4k—~3.2kAutomated safety check: PassCC-BY-SA-4.05 days ago
29

Walks through adding a new file format to remindb's Go parser package: the parser file, the ParseBytes case, table tests and fuzz seeds.

radimsem/remindb129—~1.6kAutomated safety check: PassMIT2 mo ago
30

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT2 days ago
31

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

trailofbits/skills7.4k—~2.9kAutomated safety check: PassCC-BY-SA-4.05 days ago
32

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.05 days ago
33

Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.

trailofbits/skills7.4k—~4kAutomated safety check: PassCC-BY-SA-4.05 days ago
34
34.LibaflOfficial

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

trailofbits/skills7.4k—~4.3kAutomated safety check: NotesCC-BY-SA-4.05 days ago
35
35.OssfuzzOfficial

Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.

trailofbits/skills7.4k—~4.2kAutomated safety check: PassCC-BY-SA-4.05 days ago
36
36.RuzzyOfficial

Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language.

trailofbits/skills7.4k—~3kAutomated safety check: PassCC-BY-SA-4.05 days ago
37

Guides through Trail of Bits' 5-step secure development workflow.

trailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.05 days ago
38

Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts.

alt-research2/SolidityGuard104—~763Automated safety check: NotesUnknown3 mo ago
39

Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.

trailofbits/skills7.4k—~1.1kAutomated safety check: PassCC-BY-SA-4.05 days ago
40

Discover hidden directories, files, and endpoints on a web server

NeoTheCapt/RedteamAgent140—~737Automated safety check: NotesNo licence2 mo ago
41
41.AflppOfficial

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

trailofbits/skills7.4k—~5.6kAutomated safety check: PassCC-BY-SA-4.05 days ago
42

Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output.

trailofbits/skills7.4k—~5.3kAutomated safety check: PassCC-BY-SA-4.05 days ago
43
43.LibfuzzerOfficial

Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.

trailofbits/skills7.4k—~6.1kAutomated safety check: PassCC-BY-SA-4.05 days ago
44

Table-driven testler, subtestler, benchmark'lar, fuzzing ve test coverage içeren Go test desenleri.

affaan-m/ECC274k1 repo~4.3kAutomated safety check: PassMIT2 days ago
45

Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

SnailSploit/Claude-Red7.3k—~3kAutomated safety check: WarnMIT17 days ago
46

Production-ready Golang tests — table-driven, testify suites/mocks, parallel tests, fuzzing, fixtures, goleak leak detection, snapshots, coverage, integration tests.

context-labs/whip1.1k—~4.4kAutomated safety check: PassMIT2 days ago
47

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

ash1794/vibe-engineering162—~689Automated safety check: PassMITyesterday
48

Patrones de pruebas Go incluyendo pruebas basadas en tablas, subpruebas, benchmarks, fuzzing y cobertura de código.

affaan-m/ECC274k—~4.3kAutomated safety check: PassMIT2 days ago

Questions, answered from the data.

What is the best fuzzing skill?

Fizz from pashov/skills ranks first of the 75 fuzzing skills listed here, with the highest score: its repository has 1.2k GitHub stars, 2 other GitHub owners carry a copy, its SKILL.md loads about 11k tokens and it passes the automated safety check with no findings. Next come GreptimeDB Fuzz CI Failure Investigation and Find Postgres Bug.

Which fuzzing skills are official?

13 of the 75 fuzzing skills are official, published by the vendor's own GitHub organization: Fuzzing Harness Design, Mutation Testing Triage, cargo-fuzz Rust Fuzzing, Fuzzing Dictionary Builder, Fuzzing Obstacle Patcher and 8 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.