# Ffuf Web Fuzzing

> Run targeted web fuzzing to discover hidden routes, parameters, and weak input handling in authorized environments. Use for controlled security assessments, endpoint discovery, and input validation checks.

- Skill: `nikopj01/ffuf-web-fuzzing` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add nikopj01/ffuf-web-fuzzing`
- Raw SKILL.md: https://api.skillmd.com/api/skills/nikopj01/ffuf-web-fuzzing/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Product & Planning
- Author: nikopj01 (https://skillmd.com/u/nikopj01)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/nikopj01/ffuf-web-fuzzing

---


# FFUF Web Fuzzing

## Workflow
1. Confirm explicit authorization and test scope before any fuzzing.
2. Choose focused wordlists and rate limits to minimize impact.
3. Start with endpoint discovery, then parameter and content fuzzing.
4. Triage findings by exploitability and business impact.
5. Document reproduction steps and remediation guidance.

