Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing. Trigger with phrases like "fuzz the API", "run fuzzing tests", or "discover edge cases".
Use the skills CLI to install this skill with one command. Auto-detects all installed AI assistants.
Method 1 - skills CLI
npx skills i jeremylongshore/claude-code-plugins-plus-skills/plugins/testing/api-fuzzer/skills/fuzzing-apisMethod 2 - openskills (supports sync & update)
npx openskills install jeremylongshore/claude-code-plugins-plus-skillsAuto-detects Claude Code, Cursor, Codex CLI, Gemini CLI, and more. One install, works everywhere.
Installation Path
Download and extract to one of the following locations:
No setup needed. Let our cloud agents run this skill for you.
Select Provider
Select Model
Best for coding tasks
Environment setup included
Perform API fuzzing to discover crashes, unhandled exceptions, security vulnerabilities, and edge case failures by sending malformed, unexpected, and boundary-value inputs to API endpoints. Supports RESTler (stateful REST API fuzzing), Schemathesis (OpenAPI-driven property-based testing), custom fuzz harnesses with fast-check, and OWASP ZAP active scanning.
**/openapi.yaml, **/swagger.json).%s%n), path traversal (../../etc/passwd).schemathesis run http://localhost:3000/openapi.json --stateful=links.restler-fuzzer fuzz --grammar_file grammar.py.| Error | Cause | Solution |
|---|---|---|
| Fuzzer cannot parse API spec | Invalid or incomplete OpenAPI specification | Validate the spec with swagger-cli validate; fix schema errors before fuzzing |
| All requests return 401 | Authentication not configured in fuzzer | Provide auth headers via --set-header "Authorization: Bearer TOKEN" or config file |
| Server crashes during fuzzing | Unhandled exception or resource exhaustion | Restart the server with a process manager; enable crash dump collection; add OOM killer threshold |
| Too many false positives (500 errors) | Application returns 500 for expected validation errors | Filter known error patterns; configure the fuzzer to ignore specific response bodies |
| Fuzzer generates unrealistic inputs | Schema-based generation produces impossible combinations |
Schemathesis OpenAPI fuzzing:
# Basic schema-based fuzzing
schemathesis run http://localhost:3000/api/openapi.json \ # 3000: 3 seconds in ms
--stateful=links \
--hypothesis-max-examples=500 \ # HTTP 500 Internal Server Error
--base-url=http://localhost:3000 \ # 3 seconds in ms
--header "Authorization: Bearer $TEST_TOKEN"
# With specific checks
schemathesis run http://localhost:3000/api/openapi.json \ # 3 seconds in ms
fast-check property-based API test:
import fc from 'fast-check';
import request from 'supertest';
import { app } from '../src/app';
test('POST /api/users handles arbitrary input without crashing', async () => {
await fc.assert(
fc.asyncProperty
Custom fuzz dictionary for injection testing:
[
"' OR '1'='1",
"<script>alert(1)</script>",
"${7*7}",
"{{7*7}}",
"../../../etc/passwd",
"\u0000",
"A".repeat(100000) # 100000 = configured value
]Add x-examples to the OpenAPI spec; use stateful fuzzing to maintain valid sequences |