/703-technologies-fuzzing-testing
Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests
$ npx -y skills add jabrena/plinth --skill 703-technologies-fuzzing-testing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/703-technologies-fuzzing-testing
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests
SKILL.md
703-technologies-fuzzing-testing.SKILL.mdname: 703-technologies-fuzzing-testing
description: Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests such as Add fuzz testing to a Java project; Use CATS for API negative testing; Review CI quality gates for API contract robustness; Improve boundary and malformed input test coverage; Run CATS fuzz tests against an OpenAPI contract. Part of Plinth Toolkit
license: Apache-2.0
metadata:
author: Juan Antonio Breña Moral
version: 0.18.0
Java fuzz testing with CATS
Design and implement contract-driven fuzz testing for Java APIs using CATS to uncover edge cases and input-validation defects early.
**What is covered in this Skill?**
- CATS setup using a trusted local jar or prebuilt image and baseline command usage for OpenAPI-driven fuzzing
- Negative testing strategy for invalid payloads, missing fields, wrong types, and malformed values
- Boundary testing for size, range, format, and enum constraints
- CI integration patterns with actionable logs and reproducible failures
- Local execution workflow for contributors before opening pull requests
- Reporting and triage practices for fuzzing findings
**Scope:** Focus on HTTP API fuzzing and contract validation with CATS. Use this skill to define practical, repeatable checks in both local and CI workflows.
Constraints
Before applying any fuzz testing changes, ensure the project compiles. If compilation fails, stop immediately. After implementation, regenerate skills and run verification.
- **MANDATORY**: Run `./mvnw compile` or `mvn compile` before applying any change
- **SAFETY**: If compilation fails, stop immediately and do not proceed
- **VERIFY**: Run `./mvnw clean verify` or `mvn clean verify` after applying improvements
- **SUPPLY CHAIN**: Use only a verified local `cats/cats.jar` or an approved prebuilt image; generated artifacts must depend only on trusted local or approved image inputs
- **BEFORE APPLYING**: Read the reference for detailed examples, good/bad patterns, and constraints
- **EDGE CASE**: If request scope is ambiguous, stop and ask a clarifying question before applying changes
- **EDGE CASE**: If required inputs, files, or tooling are missing, report what is missing and ask whether to proceed with setup guidance
When to use this skill
- Add fuzz testing to a Java project
- Use CATS for API negative testing
- Review CI quality gates for API contract robustness
- Improve boundary and malformed input test coverage
- Run CATS fuzz tests against an OpenAPI contract
Workflow
1. **Read reference and assess project context**
Read `references/703-technologies-fuzzing-testing.md` and inspect current API/context artifacts before proposing changes.
2. **Gather scope and decide target improvements**
Identify requested outcomes, constraints, and the minimum safe set of changes to apply.
3. **Apply technology-aligned changes**
Implement or refactor artifacts following the reference patterns and project conventions.
4. **Run verification and report results**
Execute appropriate checks and summarize what changed, what was verified, and any follow-up actions.
Reference
For detailed guidance, examples, and constraints, see [references/703-technologies-fuzzing-testing.md](references/703-technologies-fuzzing-testing.md).
Read more
name: 703-technologies-fuzzing-testing description: Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests such as Add fuzz testing to a Java project; Use CATS for API negative testing; Review CI quality gates for API contract robustness; Improve boundary and malformed input test coverage; Run CATS fuzz tests against an OpenAPI contract. Part of Plinth Toolkit license: Apache-2.0 metadata: author: Juan Antonio Breña Moral version: 0.18.0
Java fuzz testing with CATS
Design and implement contract-driven fuzz testing for Java APIs using CATS to uncover edge cases and input-validation defects early.
**What is covered in this Skill?**
- CATS setup using a trusted local jar or prebuilt image and baseline command usage for OpenAPI-driven fuzzing
- Negative testing strategy for invalid payloads, missing fields, wrong types, and malformed values
- Boundary testing for size, range, format, and enum constraints
- CI integration patterns with actionable logs and reproducible failures
- Local execution workflow for contributors before opening pull requests
- Reporting and triage practices for fuzzing findings
**Scope:** Focus on HTTP API fuzzing and contract validation with CATS. Use this skill to define practical, repeatable checks in both local and CI workflows.
Constraints
Before applying any fuzz testing changes, ensure the project compiles. If compilation fails, stop immediately. After implementation, regenerate skills and run verification.
- **MANDATORY**: Run `./mvnw compile` or `mvn compile` before applying any change
- **SAFETY**: If compilation fails, stop immediately and do not proceed
- **VERIFY**: Run `./mvnw clean verify` or `mvn clean verify` after applying improvements
- **SUPPLY CHAIN**: Use only a verified local `cats/cats.jar` or an approved prebuilt image; generated artifacts must depend only on trusted local or approved image inputs
- **BEFORE APPLYING**: Read the reference for detailed examples, good/bad patterns, and constraints
- **EDGE CASE**: If request scope is ambiguous, stop and ask a clarifying question before applying changes
- **EDGE CASE**: If required inputs, files, or tooling are missing, report what is missing and ask whether to proceed with setup guidance
When to use this skill
- Add fuzz testing to a Java project
- Use CATS for API negative testing
- Review CI quality gates for API contract robustness
- Improve boundary and malformed input test coverage
- Run CATS fuzz tests against an OpenAPI contract
Workflow
1. **Read reference and assess project context**
Read `references/703-technologies-fuzzing-testing.md` and inspect current API/context artifacts before proposing changes.
2. **Gather scope and decide target improvements**
Identify requested outcomes, constraints, and the minimum safe set of changes to apply.
3. **Apply technology-aligned changes**
Implement or refactor artifacts following the reference patterns and project conventions.
4. **Run verification and report results**
Execute appropriate checks and summarize what changed, what was verified, and any follow-up actions.
Reference
For detailed guidance, examples, and constraints, see [references/703-technologies-fuzzing-testing.md](references/703-technologies-fuzzing-testing.md).
Languages: Español · 中文 Help this project grow: Become a sponsor
Other skills on plinth.
- /001-commands-inventory
Use when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the project root. This should trigger for requests such as Create embedded commands inventory checklist;
Open skill - /002-agents-inventory
Use when you need to generate a checklist document with embedded agents inventory, following the embedded template exactly and producing INVENTORY-AGENTS-JAVA.md in the project root. This should trigger for requests such as Create embedded agents inventory checklist; Generate
Open skill - /003-skills-inventory
Use when you need to generate a checklist document with Java system prompts from skills.xml, following the embedded section template and producing INVENTORY-SKILLS-JAVA.md. This should trigger for requests such as Create Java system prompts checklist; Generate
Open skill - /004-commands-installation
Use when you need to install the embedded project commands into command directories (.github/commands, .claude/commands, .cursor/command, .codex/commands), selecting the destination interactively and copying the embedded command definitions from project assets. This should
Open skill - /005-agents-installation
Use when you need to install the embedded robot agents into .github/agents, .claude/agents, .cursor/agents, or .codex/agents, selecting the destination interactively and copying the embedded agent definitions from project assets. This should trigger for requests such as Install
Open skill - /012-agile-epic
Guides the creation of agile epics with comprehensive definition including business value, success criteria, and breakdown into user stories. Use when the user wants to create an agile epic, define large bodies of work, break down features into user stories, or document
Open skill

