Sponsor Suno AI Music arrow_forward
Slash Command

Fuzz Api

Fuzz test APIs with malformed inputs and edge cases

Type
Slash Command
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026

What Fuzz Api is

Fuzz Api is a slash command published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A slash command is a reusable prompt saved as a markdown file and run by typing its name after a slash. In Claude Code, custom commands have been merged into skills: a file in .claude/commands/ and a skill folder in .claude/skills/ both create the same kind of command, and existing command files keep working.

Fuzz Api gives you a repeatable way to run the same instructions without retyping them, optionally with arguments.

How to install Fuzz Api

Claude Code

  1. Download fuzz-api.md from the repository.
  2. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md.
  3. Run it by typing / followed by its name.

Claude Cowork

  1. Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it.
  2. In Customize → Skills, click +, then upload the ZIP.
  3. Run it from any task with / and the skill name.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/testing/api-fuzzer/commands/fuzz-api.md, shared under the repository's MIT license. Read the full file on GitHub.

Automated fuzz testing for REST APIs to discover vulnerabilities, crashes, and unexpected behavior through malformed inputs, boundary values, and random payloads. This command generates comprehensive fuzz test suites targeting injection attacks, input validation failures, and edge cases.

Design Decisions

Why fuzz testing matters:

  • Security: Discovers SQL injection, XSS, command injection vulnerabilities
  • Robustness: Finds crashes from unexpected inputs before users do
  • Edge cases: Uncovers boundary conditions developers didn't consider
  • Compliance: Validates input sanitization meets security standards

Alternatives considered:

  • Manual testing: Too slow, can't cover mutation space
  • Property-based testing: Good for unit tests, less suited for API integration
  • Penetration testing tools: Expensive, requires security expertise
  • Static analysis: Misses runtime-only issues

This approach balances: Automation, coverage, security focus, and integration with CI/CD.

When to Use

Use API fuzzing when:

  • Testing security-critical APIs (auth, payment, admin endpoints)
  • Validating input sanitization and validation logic
  • Finding edge cases before production incidents
  • Meeting security compliance requirements (PCI-DSS, SOC 2)
  • Testing third-party API integration error handling
  • Preparing for penetration testing or security audits

Don't use when:

  • API has no user input (static data endpoints)
  • Building proof-of-concept with no security requirements
  • Input validation is already exhaustively tested
  • Time-sensitive release without CI/CD integration

Prerequisites

  • Existing REST API with endpoints to test
  • Node.js 16+ or Python 3.8+ for fuzzing scripts
  • API documentation (OpenAPI/Swagger or manual endpoint list)
  • (Optional) Authentication credentials or test accounts
  • (Optional) CI/CD pipeline for automated fuzzing
  • (Optional) Security monitoring tools (SIEM, IDS)

Process

  1. Identify Attack Surface
  • List all API endpoints accepting user input
  • Identify input types (strings, numbers, JSON, files)
  • Prioritize high-risk endpoints (auth, admin, payment)
  1. Generate Fuzz Inputs
  • Malformed data (null, undefined, empty, overflow)
  • Injection payloads (SQL, XSS, command injection)
  • Boundary values (max int, negative, infinity)
  • Type confusion (string as int, object as array)
  1. Execute Fuzz Tests
  • Send fuzz inputs to all endpoints
  • Monitor responses for crashes, 500 errors, timeouts
  • Capture stack traces and error details
  1. Analyze Results
  • Categorize vulnerabilities by severity (critical, high, medium)
  • Create reproducible test cases for failures
  • Generate security report with findings
  1. Remediate and Retest
  • Fix discovered vulnerabilities
  • Add regression tests for fixed issues
  • Rerun fuzzer to verify fixes

Output Format

Jest Fuzz Test Suite (Node.js)

// tests/api-fuzzer.test.js
const axios = require('axios');

const API_BASE = process.env.API_URL || 'http://localhost:3000';

// Fuzz input generators
const fuzzInputs = {
  // String mutations
  strings: [
    '', // Empty
    null,
    undefined,
    ' ', // Whitespace
    'A'.repeat(10000), // Very long
    'A'.repeat(1000000), // Extremely long
    '<script>alert(1)</script>', // XSS
    '<img src=x onerror=alert(1)>', // XSS variant
    '${7*7}', // Template injection
…

Python REST-Assured Fuzzer

# tests/test_api_fuzzer.py
import pytest
import requests
from typing import Any, List
import string
import random

API_BASE = "http://localhost:3000"

class FuzzInputGenerator:
    """Generate various fuzz inputs for API testing"""

    @staticmethod
    def string_mutations() -> List[Any]:
        return [
            "",  # Empty
            None,
            " ",  # Whitespace
…

Example Usage

Example 1: Automated Fuzzing in CI/CD

// .github/workflows/fuzz-tests.yml
name: API Fuzz Testing

on: [push, pull_request]

jobs:
  fuzz:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v2
      - name: Start API server
        run: npm run start:test &
      - name: Wait for API
        run: npx wait-on http://localhost:3000/health
      - name: Run fuzz tests
        run: npm run test:fuzz
      - name: Upload fuzz report
        if: failure()
…

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Fuzz Api?

Fuzz Api is a slash command for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Fuzz test APIs with malformed inputs and edge cases

How do I install Fuzz Api in Claude Code?

Download fuzz-api.md from the repository. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md. Run it by typing / followed by its name.

Can I use Fuzz Api in Claude Cowork?

Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it. In Customize → Skills, click +, then upload the ZIP. Run it from any task with / and the skill name.

Is Fuzz Api safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.