File contents Testing Handbook Skills
Comprehensive security testing toolkit generated from the Trail of Bits Application Security Testing Handbook .
When to Use
Setting up fuzzing campaigns for C/C++, Rust, Python, or Ruby
Writing fuzzing harnesses for target functions
Analyzing code coverage to guide testing
Running sanitizers (AddressSanitizer, UBSan, MSan) to catch memory bugs
Performing constant-time testing for cryptographic code
Using Wycheproof test vectors for crypto validation
When NOT to Use
Smart contract auditing (use security-building-secure-contracts)
Writing custom Semgrep rules (use semgrep-rule-creator)
General code review (use security-differential-review)
Vulnerability hunting without a testing plan (use audit-context-building first)
Sub-Skills (17 total)
Fuzzers
Fuzzer
Language
Best For
Skill Path
libFuzzer
C/C++
LLVM-based coverage-guided fuzzing
skills/libfuzzer/SKILL.md
AFL++
C/C++
Advanced mutation-based fuzzing
skills/aflpp/SKILL.md
libAFL
C/C++
LibAFL-based custom fuzzers
skills/libafl/SKILL.md
cargo-fuzz
Rust
Rust native fuzzing with libFuzzer backend
skills/cargo-fuzz/SKILL.md
Atheris
Python
Python coverage-guided fuzzing
skills/atheris/SKILL.md
Ruzzy
Ruby
Ruby coverage-guided fuzzing
skills/ruzzy/SKILL.md
Techniques
Technique
Purpose
Skill Path
Harness Writing
Writing effective fuzzing harnesses
skills/harness-writing/SKILL.md
Coverage Analysis
Measuring and improving code coverage
skills/coverage-analysis/SKILL.md
Fuzzing Dictionary
Creating effective fuzzing dictionaries
skills/fuzzing-dictionary/SKILL.md
Fuzzing Obstacles
Overcoming common fuzzing barriers
skills/fuzzing-obstacles/SKILL.md
AddressSanitizer
Memory error detection with ASan
skills/address-sanitizer/SKILL.md
Static Analysis
Tool
Purpose
Skill Path
Semgrep
Fast pattern-matching security scans
skills/semgrep/SKILL.md
CodeQL
Deep semantic code analysis
skills/codeql/SKILL.md
Cryptographic Testing
Tool
Purpose
Skill Path
Wycheproof
Test vectors for crypto implementations
skills/wycheproof/SKILL.md
Constant-Time Testing
Verify constant-time crypto properties
skills/constant-time-testing/SKILL.md
Infrastructure
Tool
Purpose
Skill Path
OSS-Fuzz
Google's continuous fuzzing service
skills/ossfuzz/SKILL.md
Meta
Tool
Purpose
Skill Path
Generator
Generate new skills from the Testing Handbook
skills/testing-handbook-generator/SKILL.md
Workflow
Starting a fuzzing campaign
Choose a fuzzer based on your target language (see Fuzzers table)
Write a harness using the harness-writing skill
Build with sanitizers (AddressSanitizer recommended as baseline)
Create a seed corpus with representative inputs
Run the campaign and monitor coverage
Analyze coverage to find uncovered code and improve the harness
Triage crashes and deduplicate findings
Setting up CI/CD testing
OSS-Fuzz for open-source projects (continuous fuzzing)
Semgrep + CodeQL for static analysis in PRs
Wycheproof test vectors for crypto validation
Quick Start by Language
Language
Fuzzer
Harness
Sanitizer
C/C++
libFuzzer or AFL++
LLVMFuzzerTestOneInput
ASan + UBSan
Rust
cargo-fuzz
fuzz_target! macro
Built-in sanitizers
Python
Atheris
atheris.FuzzedDataProvider
N/A
Ruby
Ruzzy
ruzzy harness pattern
N/A
Source Material
Generated from the Trail of Bits Application Security Testing Handbook using the testing-handbook-generator meta-skill.
1 --- 2 name: testing-handbook-skills 3 description: Testing Handbook Skills 4 --- 5 # Testing Handbook Skills 6 7 Comprehensive security testing toolkit generated from the [Trail of Bits Application Security Testing Handbook](https://appsec.guide/). 8 9 ## When to Use 10 11 - Setting up fuzzing campaigns for C/C++, Rust, Python, or Ruby 12 - Writing fuzzing harnesses for target functions 13 - Analyzing code coverage to guide testing 14 - Running sanitizers (AddressSanitizer, UBSan, MSan) to catch memory bugs 15 - Performing constant-time testing for cryptographic code 16 - Using Wycheproof test vectors for crypto validation 17 18 ## When NOT to Use 19 20 - Smart contract auditing (use security-building-secure-contracts) 21 - Writing custom Semgrep rules (use semgrep-rule-creator) 22 - General code review (use security-differential-review) 23 - Vulnerability hunting without a testing plan (use audit-context-building first) 24 25 ## Sub-Skills (17 total) 26 27 ### Fuzzers 28 29 | Fuzzer | Language | Best For | Skill Path | 30 |--------|----------|----------|------------| 31 | **libFuzzer** | C/C++ | LLVM-based coverage-guided fuzzing | [skills/libfuzzer/SKILL.md](skills/libfuzzer/SKILL.md) | 32 | **AFL++** | C/C++ | Advanced mutation-based fuzzing | [skills/aflpp/SKILL.md](skills/aflpp/SKILL.md) | 33 | **libAFL** | C/C++ | LibAFL-based custom fuzzers | [skills/libafl/SKILL.md](skills/libafl/SKILL.md) | 34 | **cargo-fuzz** | Rust | Rust native fuzzing with libFuzzer backend | [skills/cargo-fuzz/SKILL.md](skills/cargo-fuzz/SKILL.md) | 35 | **Atheris** | Python | Python coverage-guided fuzzing | [skills/atheris/SKILL.md](skills/atheris/SKILL.md) | 36 | **Ruzzy** | Ruby | Ruby coverage-guided fuzzing | [skills/ruzzy/SKILL.md](skills/ruzzy/SKILL.md) | 37 38 ### Techniques 39 40 | Technique | Purpose | Skill Path | 41 |-----------|---------|------------| 42 | **Harness Writing** | Writing effective fuzzing harnesses | [skills/harness-writing/SKILL.md](skills/harness-writing/SKILL.md) | 43 | **Coverage Analysis** | Measuring and improving code coverage | [skills/coverage-analysis/SKILL.md](skills/coverage-analysis/SKILL.md) | 44 | **Fuzzing Dictionary** | Creating effective fuzzing dictionaries | [skills/fuzzing-dictionary/SKILL.md](skills/fuzzing-dictionary/SKILL.md) | 45 | **Fuzzing Obstacles** | Overcoming common fuzzing barriers | [skills/fuzzing-obstacles/SKILL.md](skills/fuzzing-obstacles/SKILL.md) | 46 | **AddressSanitizer** | Memory error detection with ASan | [skills/address-sanitizer/SKILL.md](skills/address-sanitizer/SKILL.md) | 47 48 ### Static Analysis 49 50 | Tool | Purpose | Skill Path | 51 |------|---------|------------| 52 | **Semgrep** | Fast pattern-matching security scans | [skills/semgrep/SKILL.md](skills/semgrep/SKILL.md) | 53 | **CodeQL** | Deep semantic code analysis | [skills/codeql/SKILL.md](skills/codeql/SKILL.md) | 54 55 ### Cryptographic Testing 56 57 | Tool | Purpose | Skill Path | 58 |------|---------|------------| 59 | **Wycheproof** | Test vectors for crypto implementations | [skills/wycheproof/SKILL.md](skills/wycheproof/SKILL.md) | 60 | **Constant-Time Testing** | Verify constant-time crypto properties | [skills/constant-time-testing/SKILL.md](skills/constant-time-testing/SKILL.md) | 61 62 ### Infrastructure 63 64 | Tool | Purpose | Skill Path | 65 |------|---------|------------| 66 | **OSS-Fuzz** | Google's continuous fuzzing service | [skills/ossfuzz/SKILL.md](skills/ossfuzz/SKILL.md) | 67 68 ### Meta 69 70 | Tool | Purpose | Skill Path | 71 |------|---------|------------| 72 | **Generator** | Generate new skills from the Testing Handbook | [skills/testing-handbook-generator/SKILL.md](skills/testing-handbook-generator/SKILL.md) | 73 74 ## Workflow 75 76 ### Starting a fuzzing campaign 77 78 1. **Choose a fuzzer** based on your target language (see Fuzzers table) 79 2. **Write a harness** using the harness-writing skill 80 3. **Build with sanitizers** (AddressSanitizer recommended as baseline) 81 4. **Create a seed corpus** with representative inputs 82 5. **Run the campaign** and monitor coverage 83 6. **Analyze coverage** to find uncovered code and improve the harness 84 7. **Triage crashes** and deduplicate findings 85 86 ### Setting up CI/CD testing 87 88 1. **OSS-Fuzz** for open-source projects (continuous fuzzing) 89 2. **Semgrep + CodeQL** for static analysis in PRs 90 3. **Wycheproof** test vectors for crypto validation 91 92 ## Quick Start by Language 93 94 | Language | Fuzzer | Harness | Sanitizer | 95 |----------|--------|---------|-----------| 96 | C/C++ | libFuzzer or AFL++ | `LLVMFuzzerTestOneInput` | ASan + UBSan | 97 | Rust | cargo-fuzz | `fuzz_target!` macro | Built-in sanitizers | 98 | Python | Atheris | `atheris.FuzzedDataProvider` | N/A | 99 | Ruby | Ruzzy | `ruzzy` harness pattern | N/A | 100 101 ## Source Material 102 103 Generated from the [Trail of Bits Application Security Testing Handbook](https://appsec.guide/) using the testing-handbook-generator meta-skill.
ComeOnOliver/skillshub/tree/main/skills/elizaOS/eliza/testing-handbook-skills commit 47f5e91ac6
Frequently asked questions How do I install the Testing Handbook Skills skill? Run npx skillmds@latest add comeonoliver/testing-handbook-skills in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
What does the Testing Handbook Skills skill do? Testing Handbook Skills It is listed under Coding & Dev Tools on SkillMD.
Is Testing Handbook Skills safe to use? This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
Which AI agents work with Testing Handbook Skills? This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Is Testing Handbook Skills free to use? Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Who published Testing Handbook Skills? ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.