Install
$ agentstack add skill-ash1794-vibe-engineering-fuzz-parser-inputs ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
vibe-fuzz-parser-inputs
Every parser will eventually see input you didn't expect. Fuzz testing finds the crashes before production does.
When to Use This Skill
- Implementing any parser (YAML, JSON, XML, config, DSL)
- Processing user-supplied input
- Handling webhook payloads or API responses
- Parsing file formats
When NOT to Use This Skill
- The parser is a well-tested standard library (e.g.,
encoding/json) - You're only reading known, controlled input
- The parser is trivial (e.g., splitting a string by comma)
Steps
Go Fuzz Tests
- Create fuzz test file (
parser_fuzz_test.go):
```go func FuzzParseConfig(f testing.F) { // Seed corpus from existing test fixtures files, := filepath.Glob("testdata/.yaml") for , file := range files { data, _ := os.ReadFile(file) f.Add(data) }
// Add targeted seeds f.Add([]byte("")) // empty f.Add([]byte("{}")) // minimal valid f.Add([]byte("\x00\x00")) // binary
f.Fuzz(func(t *testing.T, data []byte) { // Should never panic result, err := ParseConfig(data) if err != nil { return // errors are fine } // If no error, result should be valid if result.Name == "" { t.Error("parsed successfully but Name is empty") } }) } ```
- Seed the corpus from:
- Existing test fixtures
- Real production examples
- Known edge cases
- Minimally valid inputs
- Binary/garbage data
- Run initial fuzz:
``bash go test -fuzz=FuzzParseConfig -fuzztime=30s ``
- Record results:
- Crashes found
- New corpus entries generated
- Edge cases discovered
- Fix crashes -- Every panic or unexpected behavior becomes a permanent test case
Other Languages
- JavaScript/TypeScript: Use
jest-fuzzorfast-checkproperty-based testing - Python: Use
hypothesisfor property-based testing - Rust: Use
cargo-fuzzwithlibfuzzer
Output Format
Fuzz Test: [Parser Name]
Seeds: X (Y from fixtures, Z manual) Duration: [fuzz time] Corpus growth: X -> Y entries (Z% expansion) Crashes found: N
| # | Input (hex) | Crash Type | Fix | |---|-------------|-----------|-----| | 1 | \x00\xff... | nil panic in tokenizer | Added nil check at line 42 |
New Edge Cases Discovered
- [Description] -- added as permanent test case
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ash1794
- Source: ash1794/vibe-engineering
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.