Build custom fuzzers with LibAFL
Compose LibAFL's modular Rust components — observers, feedbacks, mutators, schedulers, executors — into custom fuzzers, or use it as a libFuzzer drop-in
- What
- Compose LibAFL's modular Rust components — observers, feedbacks, mutators, schedulers, executors — into custom fuzzers, or use it as a libFuzzer drop-in
- Cost
- Free
- Needs
- Linux or macOS; Clang/LLVM 15-18 and Rust installed (nightly Rust for libFuzzer compatibility mode); a fuzzing target with source access — only fuzz code you own or are authorized to test
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security research tool: only fuzz targets you own or are authorized to test.** @trailofbits' guide to LibAFL, the modular Rust fuzzing library: when to choose it over libFuzzer or AFL++, drop-in libFuzzer replacement mode, and the full custom-fuzzer path — composing observers, feedbacks, objectives, mutators, schedulers and executors in Rust, crash deduplication via backtrace hashing, dictionary and auto-token fuzzing, multi-core campaigns with a TUI, compiler-wrapper instrumentation, plus complete libpng and CMake walkthroughs and a troubleshooting table. By @trailofbits, listed here with credit to its creator. Honest caveats: heavy prerequisites (Clang/LLVM 15-18, Rust, Linux/macOS); LibAFL evolves fast — pin a compatible version. License CC-BY-SA-4.0. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Linux or macOS; Clang/LLVM 15-18 and Rust installed (nightly Rust for libFuzzer compatibility mode); a fuzzing target with source access — only fuzz code you own or are authorized to test Install "Build custom fuzzers with LibAFL" for me. It gives the agent @trailofbits' LibAFL playbook: choosing LibAFL over libFuzzer/AFL++, drop-in libFuzzer mode, and composing modular Rust components (observers, feedbacks, mutators, schedulers, executors) into a bespoke fuzzer — crash deduplication, dictionary fuzzing, multi-core campaigns, libpng and CMake walkthroughs. CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/testing-handbook-skills/skills/libafl/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "libafl". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install Clang/LLVM 15-18 and Rust, clone the LibAFL repo, build the runtime before first use). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.