Fuzz Api
Fuzz test APIs with malformed inputs and edge cases
- Type
- Slash Command
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- plugins/testing/api-fuzzer/commands/fuzz-api.md
What Fuzz Api is
Fuzz Api is a slash command published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A slash command is a reusable prompt saved as a markdown file and run by typing its name after a slash. In Claude Code, custom commands have been merged into skills: a file in .claude/commands/ and a skill folder in .claude/skills/ both create the same kind of command, and existing command files keep working.
Fuzz Api gives you a repeatable way to run the same instructions without retyping them, optionally with arguments.
How to install Fuzz Api
Claude Code
- Download fuzz-api.md from the repository.
- Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md.
- Run it by typing / followed by its name.
Claude Cowork
- Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it.
- In Customize → Skills, click +, then upload the ZIP.
- Run it from any task with / and the skill name.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/testing/api-fuzzer/commands/fuzz-api.md, shared under the repository's MIT license. Read the full file on GitHub.
Automated fuzz testing for REST APIs to discover vulnerabilities, crashes, and unexpected behavior through malformed inputs, boundary values, and random payloads. This command generates comprehensive fuzz test suites targeting injection attacks, input validation failures, and edge cases.
Design Decisions
Why fuzz testing matters:
- Security: Discovers SQL injection, XSS, command injection vulnerabilities
- Robustness: Finds crashes from unexpected inputs before users do
- Edge cases: Uncovers boundary conditions developers didn't consider
- Compliance: Validates input sanitization meets security standards
Alternatives considered:
- Manual testing: Too slow, can't cover mutation space
- Property-based testing: Good for unit tests, less suited for API integration
- Penetration testing tools: Expensive, requires security expertise
- Static analysis: Misses runtime-only issues
This approach balances: Automation, coverage, security focus, and integration with CI/CD.
When to Use
Use API fuzzing when:
- Testing security-critical APIs (auth, payment, admin endpoints)
- Validating input sanitization and validation logic
- Finding edge cases before production incidents
- Meeting security compliance requirements (PCI-DSS, SOC 2)
- Testing third-party API integration error handling
- Preparing for penetration testing or security audits
Don't use when:
- API has no user input (static data endpoints)
- Building proof-of-concept with no security requirements
- Input validation is already exhaustively tested
- Time-sensitive release without CI/CD integration
Prerequisites
- Existing REST API with endpoints to test
- Node.js 16+ or Python 3.8+ for fuzzing scripts
- API documentation (OpenAPI/Swagger or manual endpoint list)
- (Optional) Authentication credentials or test accounts
- (Optional) CI/CD pipeline for automated fuzzing
- (Optional) Security monitoring tools (SIEM, IDS)
Process
- Identify Attack Surface
- List all API endpoints accepting user input
- Identify input types (strings, numbers, JSON, files)
- Prioritize high-risk endpoints (auth, admin, payment)
- Generate Fuzz Inputs
- Malformed data (null, undefined, empty, overflow)
- Injection payloads (SQL, XSS, command injection)
- Boundary values (max int, negative, infinity)
- Type confusion (string as int, object as array)
- Execute Fuzz Tests
- Send fuzz inputs to all endpoints
- Monitor responses for crashes, 500 errors, timeouts
- Capture stack traces and error details
- Analyze Results
- Categorize vulnerabilities by severity (critical, high, medium)
- Create reproducible test cases for failures
- Generate security report with findings
- Remediate and Retest
- Fix discovered vulnerabilities
- Add regression tests for fixed issues
- Rerun fuzzer to verify fixes
Output Format
Jest Fuzz Test Suite (Node.js)
// tests/api-fuzzer.test.js
const axios = require('axios');
const API_BASE = process.env.API_URL || 'http://localhost:3000';
// Fuzz input generators
const fuzzInputs = {
// String mutations
strings: [
'', // Empty
null,
undefined,
' ', // Whitespace
'A'.repeat(10000), // Very long
'A'.repeat(1000000), // Extremely long
'<script>alert(1)</script>', // XSS
'<img src=x onerror=alert(1)>', // XSS variant
'${7*7}', // Template injection
…Python REST-Assured Fuzzer
# tests/test_api_fuzzer.py
import pytest
import requests
from typing import Any, List
import string
import random
API_BASE = "http://localhost:3000"
class FuzzInputGenerator:
"""Generate various fuzz inputs for API testing"""
@staticmethod
def string_mutations() -> List[Any]:
return [
"", # Empty
None,
" ", # Whitespace
…Example Usage
Example 1: Automated Fuzzing in CI/CD
// .github/workflows/fuzz-tests.yml
name: API Fuzz Testing
on: [push, pull_request]
jobs:
fuzz:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Start API server
run: npm run start:test &
- name: Wait for API
run: npx wait-on http://localhost:3000/health
- name: Run fuzz tests
run: npm run test:fuzz
- name: Upload fuzz report
if: failure()
… Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Fuzz Api?
Fuzz Api is a slash command for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Fuzz test APIs with malformed inputs and edge cases
How do I install Fuzz Api in Claude Code?
Download fuzz-api.md from the repository. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md. Run it by typing / followed by its name.
Can I use Fuzz Api in Claude Cowork?
Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it. In Customize → Skills, click +, then upload the ZIP. Run it from any task with / and the skill name.
Is Fuzz Api safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Sync Agent Context Merge all AGENTS.md files into CLAUDE.md for unified agent context Slash Command · jeremylongshore/tons-of-skills-marketplace
- Sugar Task Create a comprehensive Sugar task with rich context and metadata Slash Command · jeremylongshore/tons-of-skills-marketplace
- Synthetic Monitoring Setup Set up synthetic monitoring for proactive performance tracking Plugin · jeremylongshore/tons-of-skills-marketplace
- Task Planner Strategic task planning and breakdown specialist for complex development work Subagent · jeremylongshore/tons-of-skills-marketplace
- Gen Doubles Generate test doubles (mocks, stubs, spies, fakes) for unit testing Slash Command · jeremylongshore/tons-of-skills-marketplace
- Firestore Setup Initialize Firebase Admin SDK, configure Firestore, and setup A2A/MCP Slash Command · jeremylongshore/tons-of-skills-marketplace
- Gen Report Generate comprehensive test reports with coverage and trends Slash Command · jeremylongshore/tons-of-skills-marketplace
- Find Best Route Find optimal DEX routing for token swaps Slash Command · jeremylongshore/tons-of-skills-marketplace