Fuzz Rust projects with cargo-fuzz
Set up and run cargo-fuzz — harness writing, nightly toolchain, sanitizers, coverage, crash triage
- What
- Set up and run cargo-fuzz — harness writing, nightly toolchain, sanitizers, coverage, crash triage
- Cost
- Free
- Needs
- Rust and Cargo via rustup, the nightly toolchain (rustup install nightly), then cargo install cargo-fuzz. Authorized testing only — your own code or authorized assessments.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT**: Trail of Bits' cargo-fuzz guide — the standard fuzzer for Cargo-based Rust projects: install the nightly toolchain and cargo-fuzz, write `fuzz_target!` harnesses (library-crate structure, harness do/don't rules, structure-aware fuzzing with the `arbitrary` crate), run campaigns (sanitizer options including AddressSanitizer, dictionaries, seed corpus, re-executing crashes, interpreting output), measure coverage with llvm-tools and a report script, with a full worked example on the ogg crate and a troubleshooting table. Kept by editorial choice as a borderline case: fuzzing finds real vulnerabilities — use it on your own code or within authorized testing only. Honest caveats: requires the nightly Rust toolchain; the multi-core fuzzing feature is experimental; CC-BY-SA-4.0 licensed (share-alike). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Rust and Cargo via rustup, the nightly toolchain (rustup install nightly), then cargo install cargo-fuzz. Authorized testing only — your own code or authorized assessments. Install "Fuzz Rust projects with cargo-fuzz" for me. It teaches cargo-fuzz: installation, writing fuzz_target! harnesses (library-crate structure, arbitrary-crate structure-aware fuzzing), running campaigns (sanitizers, dictionaries, corpus), reproducing and triaging crash artifacts, coverage analysis, with a worked ogg-crate example — by Trail of Bits, CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/testing-handbook-skills/skills/cargo-fuzz/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "cargo-fuzz". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the nightly toolchain and cargo-fuzz; structure my target code as a library crate before fuzzing). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.