Automates fuzzing operations from setup and execution to coverage reporting and preservation.
Install
mkdir -p .claude/skills/corpus-management && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/10279" && unzip -o skill.zip -d .claude/skills/corpus-management && rm skill.zipInstalls to .claude/skills/corpus-management
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Manage fuzzing corpus lifecycle: SSD/scratch setup, fuzzer execution, coverage collection, corpus merge and dedup, and artifact preservation.Key capabilities
- →Setup scratch storage
- →Run fuzzers
- →Collect coverage
- →Merge and dedup corpus
- →Preserve artifacts
How it works
It manages the fuzzing lifecycle by setting up storage, executing fuzzers, merging coverage data, and cleaning up artifacts.
Inputs & outputs
When to use corpus-management
- →Run fuzzing tests
- →Collect fuzzing coverage
- →Clean up corpus artifacts
About this skill
Corpus Management
Overview
Manage fuzzing corpus across permanent (cfl/corpus-*/) and scratch/SSD
storage. Covers setup, fuzzing, coverage, merge, dedup, and cleanup.
Workflow
1. Setup Scratch Storage
# Optional SSD/scratch root for corpus pruning or long runs.
SCRATCH=/mnt/fuzz-ssd
mkdir -p "$SCRATCH"/logs "$SCRATCH"/profraw
for d in cfl/corpus-*; do rsync -a --ignore-existing "$d/" "$SCRATCH/$(basename "$d")/"; done
# Status check
for d in cfl/corpus-*/; do
name=$(basename "$d" | sed 's/^corpus-//'); count=$(ls "$d" 2>/dev/null | wc -l)
printf "%-40s %6d files\n" "$name" "$count"
done
2. Run Fuzzers
# All fuzzers (sequential, prevents OOM)
cd cfl && ./fuzz-local.sh
# Single fuzzer smoke test (60s)
ASAN_OPTIONS=detect_leaks=0 LLVM_PROFILE_FILE=/dev/null \
cfl/bin/icc_dump_fuzzer -max_total_time=60 -timeout=30 \
-rss_limit_mb=4096 cfl/corpus-icc_dump_fuzzer/
Special flags: icc_link_fuzzer needs quarantine_size_mb=256.
fuzz-local.sh copies the pure ICC fixtures from cfl/seeds-applynamedcmm/
into the NamedCmm runtime corpus before executing that target. Never fuzz the
tracked seed directory in place, and never prepend harness controls to those
profiles.
If ICS-POC/ is available, the same installer copies the five package ICC/
directories with package-prefixed names. Override discovery with
CFL_ICS_POC_ROOT; do not copy package TIFF, PNG, XML, or data files into the
pure-profile corpus.
For the aligned NamedCmm, Connect, config, and JSON/XML conversion lanes, keep
max_len = 0; the CFL runners derive the explicit runtime limit from the
largest corpus file. Put representative large inputs in the corpus instead of
adding a fixed size ceiling. Bound resource use with the existing RSS and
per-input timeout settings.
Install the schema-shaped
docs/Testing/json-configs/connect-config-complete.json directly into the CFL
config corpus as ordinary JSON; do not prepend a selector byte. The three AFL
-cfg lanes share that fixture and cfl/icc_cfg.dict, but continue to
screen it through their real tools from isolated work directories. Connect
profile controls belong only after the profile's declared ICC payload.
3. Collect Coverage
# Clear stale profraw (invalidated by rebuild)
find . /mnt/fuzz-ssd -name '*.profraw' -type f -delete
# Merge and report
llvm-profdata-18 merge -sparse /path/profraw/*.profraw -o merged.profdata
OBJS=$(printf ' -object %s' cfl/bin/icc_*_fuzzer)
llvm-cov-18 report $OBJS -instr-profile=merged.profdata
4. Preserve Artifacts
Copy crash/oom/timeout files BEFORE cleaning storage:
rsync -a --ignore-existing cfl/runs/*/artifacts/crash-* ./ 2>/dev/null
rsync -a --ignore-existing cfl/runs/*/artifacts/timeout-* ./test-profiles/cwe-400/ 2>/dev/null
5. Corpus Merge (Tournament Bracket)
LibFuzzer -merge=1 is single-threaded. For large corpora, use parallel merge:
# Small corpora (<500 files): 11 parallel merges
ASAN_OPTIONS=detect_leaks=0 LLVM_PROFILE_FILE=/dev/null
for name in applynamedcmm applyprofiles dump fromcube fromxml link roundtrip specsep tiffdump toxml v5dspobs; do
mkdir -p /tmp/merge/${name}
taskset -c $((RANDOM % $(nproc))) \
cfl/bin/icc_${name}_fuzzer -merge=1 -timeout=10 -rss_limit_mb=2048 \
/tmp/merge/${name} cfl/corpus-icc_${name}_fuzzer/ &
done
wait
For 1K+ file corpora, use tournament bracket (split into N=nproc chunks, merge each on its own core, pair results 16->8->4->2->1).
6. Verify and Swap
Compare file counts (local must be >= source) before swapping directories.
Key Rules
- After rebuilding fuzzers, ALL old profraw is invalid (binary hash mismatch)
- Use
${fuzzer_name}_%m_%p.profrawnaming (not just%m.profraw) - ALL batch operations MUST use all available CPU cores
- Use existing
.github/scripts/corpus-merge.sh-- do NOT create custom scripts - Only corpus dirs matching
cfl/fuzzers.share runnable;corpus-xmlis a staging area - AFL
jpegdumpandjpegdump-injectseed only up to 200.jpg/.jpegfiles fromfuzz/graphics/jpgwith extractable embedded ICC profiles; never seed those lanes with raw.iccfiles. - AFL
applyprofiles-hybrid-embeddedkeeps the complete generated multispectral TIFF. Install the pinned large-input runtime with./afl/build-afl-runtime.shand run.github/scripts/validate-afl-target-configs.sh --local; do not crop the seed to fit an older AFL++ runtime. - AFL ProfilePlot lanes share the durable
test-profiles/sRGB_v4_ICC_preference.iccfixture. Graph seeds must retainchroma:xy; raster seeds must retainclut:A2B0. Screen both with exit zero and validate the raw-output path with.github/scripts/validate-afl-profileplot-targets.sh --replay. - AFL inputs, queues, and findings are separate: seeds live in
input/, while a single AFL instance writesoutput/default/queueand parallel instances writeoutput/main/queueplusoutput/secondary_N/queue. Do not copy XML sidecars into a queue or crashes directory. - Replay
fromxml-includesfrom its staged support working directory. Use the AFL triage/map/minimize helpers so relative TXT/XML includes resolve. JSON-cfglanes must use their isolatedafl/work/<target>/rootdirectory so fuzzed output names cannot litter the repository root. applyprofiles-hybrid-pcchas one known-compatible PCC seed and a slow full transform. Keep its focused seed set and measured timeout; broad corpus screening can look like a hung startup before AFL creates stats.applynamedcmm-hybrid-pccfuzzes only V5 ICC profiles in its PCC position, always stages the generated D50 PCC profile, and may discover the five ICS packageICC/directories throughAFL_ICS_POC_ROOT. Do not admit XML or generated TIFF files to this lane; inventory those sources separately and send media only to a matching media target.applynamedcmm-v5-brdfusesextended-test-profiles/tag-checks/dtob-brdf.iccwith selector10063. Keepapplynamedcmm-hybrid-chainon explicit spectral selector10103so BRDF-direct and spectral V5 coverage do not collapse into the same lane.- The ordinary
applynamedcmmlane always stages its known sRGB profile and requires directory candidates to complete its fixed RGB intent-3 transform with exit 0. The validated explicit bootstrap bypasses runtime corpus screening; keep soft-failing directory profiles in parser lanes instead of counting them as apply coverage. applyprofiles-hybrid-embeddedmust retain the full multispectral TIFF but skip enhanced deterministic inference, use fast calibration, and enable expanded havoc immediately. The inference stage can displayzzzz...for minutes on this multi-megabyte structured seed without useful mutation work.- On repeated correction or wrap-up requests, skip broad corpus sweeps. Make the named fix, run the narrow seed validator or seed-only check, then commit and push if requested.
References
.github/prompts/fuzzer-optimization.prompt.md-- Coverage strategies.github/instructions/cfl.instructions.md-- Fuzzer details
When not to use it
- →Running fuzzers outside of defined corpus directories
Prerequisites
Limitations
- →Requires matching corpus directories
How it compares
It provides a standardized lifecycle management workflow instead of manual fuzzer execution.
Compared to similar skills
corpus-management side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| corpus-management (this skill) | 0 | 4mo | Review | Advanced |
| investigate | 0 | 5mo | No flags | Intermediate |
| python-testing-patterns | 77 | 4mo | Review | Intermediate |
| chrome-devtools | 41 | 8mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
investigate
YokoyamaRyota
|
python-testing-patterns
wshobson
Implement comprehensive testing strategies with pytest, fixtures, mocking, and test-driven development. Use when writing Python tests, setting up test suites, or implementing testing best practices.
chrome-devtools
mrgoonie
Browser automation, debugging, and performance analysis using Puppeteer CLI scripts. Use for automating browsers, taking screenshots, analyzing performance, monitoring network traffic, web scraping, form automation, and JavaScript debugging.
bats
OleksandrKucherenko
Bash Automated Testing System (BATS) for TDD-style testing of shell scripts. Use when: (1) Writing unit or integration tests for Bash scripts, (2) Testing CLI tools or shell functions, (3) Setting up test infrastructure with setup/teardown hooks, (4) Mocking external commands (curl, git, docker), (5) Generating JUnit reports for CI/CD, (6) Debugging test failures or flaky tests, (7) Implementing test-driven development for shell scripts.
wp-testing-core
mikkelkrogsholm
Core WordPress testing procedures and patterns for browser-based plugin testing. Use when testing WordPress plugins, logging into WordPress admin, verifying plugin activation, or navigating WordPress UI.
browser-daemon
noiv
Persistent browser automation via Playwright daemon. Keep a browser window open and send it commands (navigate, execute JS, inspect console). Perfect for interactive debugging, development, and testing web applications. Use when you need to interact with a browser repeatedly without opening/closing it.