AddressSanitizer: catch memory errors in C, C++ and Rust
Build and run code under AddressSanitizer to catch buffer overflows, use-after-free and leaks during fuzzing and tests
- What
- Build and run code under AddressSanitizer to catch buffer overflows, use-after-free and leaks during fuzzing and tests
- Cost
- Free
- Needs
- a C/C++ or Rust project with clang or gcc; for fuzzing, one of libFuzzer, AFL++, cargo-fuzz or honggfuzz
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a Trail of Bits testing-handbook skill on AddressSanitizer (ASan): how to instrument builds with `-fsanitize=address`, the key `ASAN_OPTIONS` (verbosity, abort-on-error, leak detection), reading crash reports and stack traces, LeakSanitizer usage, and the overhead and platform trade-offs (2–4x slowdown, full support on Linux, limited on macOS, experimental on Windows). Covers tool-specific wiring for libFuzzer, AFL++, cargo-fuzz and honggfuzz (including the 20TB virtual-memory requirement and why you must disable fuzzer memory limits), troubleshooting ("ASan runtime not initialized", false positives, performance cliffs), and the anti-patterns that matter — notably never running ASan-instrumented binaries in production. Honest caveats: fuzzing-target advice — skip for pure safe languages without FFI; CC-BY-SA-4.0 licensed (share-alike applies to reuse of the content). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a C/C++ or Rust project with clang or gcc; for fuzzing, one of libFuzzer, AFL++, cargo-fuzz or honggfuzz Install "AddressSanitizer: catch memory errors in C, C++ and Rust" for me. From Trail of Bits' testing handbook: how to build and run code under AddressSanitizer — -fsanitize=address builds, ASAN_OPTIONS, reading crash reports, LeakSanitizer, fuzzer wiring (libFuzzer, AFL++, cargo-fuzz, honggfuzz), troubleshooting and anti-patterns — CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/testing-handbook-skills/skills/address-sanitizer/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "address-sanitizer". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. rebuild my fuzz target with -fsanitize=address -g and disable fuzzer memory limits). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.