skill
offensive-fuzzing
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage. Use when setting up or running fuzz campaigns against any target: file parsers, network protocols, kernel drivers, EDR engines, embedded firmware, or language runtimes.
Description as published by the maintainer. Source
- slowing
slowing — Most recent push to the repository was 2026-05-08.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 2,838 | Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. | cumulative, all time | GitHub | |
| Last commit | 2026-05-08 | Most recent push to the containing repository. It may reflect work on a different skill in the same collection. | point in time | GitHub | |
| repository status | active | The repository holding this skill exists and is not archived. | as of fetch | GitHub |
Will this work with your setup?
Install location suggests this is meant for claude-code. The author tagged this repository "claude-skills" on GitHub. That is their statement of intent, not a test result.
We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.
The skill definition lives at Skills/fuzzing/offensive-fuzzing/SKILL.md in https://github.com/SnailSploit/Claude-Red.
Where to get it
Also from snailsploit
-
snailsploit-claude-red-offensive-active-directory
— last commit 2026-05-08
Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, Power…
-
snailsploit-claude-red-offensive-business-logic
— last commit 2026-05-08
Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations,…
-
snailsploit-claude-red-offensive-cloud
— last commit 2026-05-08
Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars,…
-
snailsploit-claude-red-offensive-iot
— last commit 2026-05-08
IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C E…
-
snailsploit-claude-red-offensive-jwt
— last commit 2026-05-08
JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret br…
-
snailsploit-claude-red-offensive-mobile
— last commit 2026-05-08
Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, c…
-
snailsploit-claude-red-offensive-osint
— last commit 2026-05-08
Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnais…
-
snailsploit-claude-red-offensive-reporting
— last commit 2026-05-08
Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for…
-
snailsploit-claude-red-offensive-shellcode
— last commit 2026-05-08
Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implemen…
-
snailsploit-claude-red-offensive-toctou
— last commit 2026-05-08
Time-of-Check / Time-of-Use (TOCTOU) race condition exploitation methodology across binary, kernel, filesystem, web, an…
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/skill.json