Topic · Security
Best fuzzing skills for Claude Code, Codex and other agents.
- skills
- 75
- official
- 13
Fuzzing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Fizz Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects. | pashov/ | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code. | GreptimeTeam/ | 6.7k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 3 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | 9 days ago |
| 4 | Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage. | antoniopaya22/ | 172 | 9 repos | ~4.2k | Automated safety check: Pass | No licence | 6 mo ago |
| 5 | Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. | pashov/ | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | Reconcile an existing Fizz harness with a changed source tree. | pashov/ | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | Treat an open-ended investigation the way a fuzzer treats a program. | ARA-Labs/ | 690 | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 8 | Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims. | inkline/ | 1.5k | — | ~1.2k | Automated safety check: Pass | No licence | 26 days ago |
| 9 | 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. | tanweai/ | 185 | — | ~847 | Automated safety check: Pass | No licence | 8 mo ago |
| 10 | Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware. | tihanyin/ | 105 | — | ~5.1k | Automated safety check: Pass | MIT | 14 days ago |
| 11 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI… | jabrena/ | 445 | — | ~874 | Automated safety check: Pass | Apache-2.0 | today |
| 13 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 613 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute). | opensage-agent/ | 127 | — | ~542 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 15 | Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security. | aviggiano/ | 144 | — | ~584 | Automated safety check: Pass | MIT | 21 days ago |
| 16 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | 6 days ago |
| 17 | Adds a new Go fuzz target to remindb following its seed-corpus discipline: one target per logical surface, discovered automatically by its FuzzXxx function name. | radimsem/ | 129 | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 18 | Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan. | InternationalColorConsortium/ | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | today |
| 19 | 19.Fuzz Testing Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s. | s3s-project/ | 311 | — | ~838 | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 134 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 21 | Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects. | aviggiano/ | 144 | — | ~2.8k | Automated safety check: Pass | MIT | 21 days ago |
| 22 | Production-ready Golang tests — table-driven tests, testify suites and mocks, parallel tests, fuzzing, fixtures, goroutine leak detection with goleak, snapshot testing, code coverage, integration… | unxed/ | 240 | 1 repo | ~4.5k | Automated safety check: Pass | MIT | today |
| 23 | Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 4 days ago |
| 24 | Extract crash inputs from fuzzing output into a target directory. | opensage-agent/ | 127 | — | ~215 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 25 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 26 | 26.Web2 Recon Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. | Gabson0x/ | 443 | — | ~1.6k | Automated safety check: Pass | No licence | 20 days ago |
| 27 | Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans. | AgentSecOps/ | 219 | 1 repo | ~3.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 28 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 29 | Walks through adding a new file format to remindb's Go parser package: the parser file, the ParseBytes case, table tests and fuzz seeds. | radimsem/ | 129 | — | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | 30.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 31 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.4k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 32 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 33 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 34 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 35 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.4k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 36 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.4k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 37 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 38 | Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts. | alt-research2/ | 104 | — | ~763 | Automated safety check: Notes | Unknown | 3 mo ago |
| 39 | Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 140 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 41 | Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. | trailofbits/ | 7.4k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 42 | Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output. | trailofbits/ | 7.4k | — | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 43 | Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang. | trailofbits/ | 7.4k | — | ~6.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | Table-driven testler, subtestler, benchmark'lar, fuzzing ve test coverage içeren Go test desenleri. | affaan-m/ | 274k | 1 repo | ~4.3k | Automated safety check: Pass | MIT | 2 days ago |
| 45 | Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies… | SnailSploit/ | 7.3k | — | ~3k | Automated safety check: Warn | MIT | 17 days ago |
| 46 | Production-ready Golang tests — table-driven, testify suites/mocks, parallel tests, fuzzing, fixtures, goleak leak detection, snapshots, coverage, integration tests. | context-labs/ | 1.1k | — | ~4.4k | Automated safety check: Pass | MIT | 2 days ago |
| 47 | Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). | ash1794/ | 162 | — | ~689 | Automated safety check: Pass | MIT | yesterday |
| 48 | Patrones de pruebas Go incluyendo pruebas basadas en tablas, subpruebas, benchmarks, fuzzing y cobertura de código. | affaan-m/ | 274k | — | ~4.3k | Automated safety check: Pass | MIT | 2 days ago |
Questions, answered from the data.
What is the best fuzzing skill?
Fizz from pashov/skills ranks first of the 75 fuzzing skills listed here, with the highest score: its repository has 1.2k GitHub stars, 2 other GitHub owners carry a copy, its SKILL.md loads about 11k tokens and it passes the automated safety check with no findings. Next come GreptimeDB Fuzz CI Failure Investigation and Find Postgres Bug.
Which fuzzing skills are official?
13 of the 75 fuzzing skills are official, published by the vendor's own GitHub organization: Fuzzing Harness Design, Mutation Testing Triage, cargo-fuzz Rust Fuzzing, Fuzzing Dictionary Builder, Fuzzing Obstacle Patcher and 8 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34