Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

differential-fuzzer差分模糊器

Agent Skill

differential-fuzzer 用于记录任务执行中的错误、用户纠正、经验和能力缺口,适合在 Codex、Claude、Cursor、Gemini CLI 中希望让 Agent 持续沉淀问题、修正和最佳实践时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

12,254

周安装

521

GitHub Stars

18,410

下载量

4,293
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:differential-fuzzer(差分模糊器)
来源仓库:https://github.com/tursodatabase/turso
仓库路径:skills/differential-fuzzer
安装命令:
npx skills add https://github.com/tursodatabase/turso --skill differential-fuzzer
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/tursodatabase/turso --skill differential-fuzzer

简介

基于属性的模糊器,将 Turso 与 SQLite 进行比较以捕获 SQL 正确性错误。

  • 生成随机 SQL 语句和架构,然后在 Turso 和 SQLite 上执行它们以检测行集、错误处理或架构状态中的不匹配
  • 通过基于种子的运行、可配置的语句/表/列计数以及用于调试的详细输出支持确定性再现
  • 包括用于扩展模糊测试活动的连续循环模式和用于 CI 的 Docker 运行程序,具有可配置的超时、GitHub 问题自动归档和 Slack 通知
  • 输出详细日志(test.sql, 架构.json)并根据需要保留数据库文件以进行手动检查和最小化复制器创建

SKILL.md

Differential Fuzzer

Always load Debugging skill for reference

The differential fuzzer compares Turso results against SQLite for generated SQL statements to find correctness bugs.

Location

testing/differential-oracle/fuzzer/

Running the Fuzzer

Single Run

# Basic run (100 statements, random seed)
cargo run --bin differential_fuzzer

# With specific seed for reproducibility
cargo run --bin differential_fuzzer -- --seed 12345

# More statements with verbose output
cargo run --bin differential_fuzzer -- -n 1000 --verbose

# Keep database files after run (for debugging)
cargo run --bin differential_fuzzer -- --seed 12345 --keep-files

# All options
cargo run --bin differential_fuzzer -- \
  --seed <SEED>           # Deterministic seed
  -n <NUM>                # Number of statements (default: 100)
  -t <NUM>                # Number of tables (default: 2)
  -c <NUM>                # Columns per table (default: 5)
  --verbose               # Print each SQL statement
  --keep-files            # Persist .db files to disk

Continuous Fuzzing (Loop Mode)

# Run forever with random seeds
cargo run --bin differential_fuzzer -- loop

# Run 50 iterations
cargo run --bin differential_fuzzer -- loop 50

Docker Runner (CI/Production)

# Build and run from repo root
docker build -f testing/differential-oracle/fuzzer/docker-runner/Dockerfile -t fuzzer .
docker run -e GITHUB_TOKEN=xxx -e SLACK_WEBHOOK_URL=xxx fuzzer

Environment variables for docker-runner:

  • TIME_LIMIT_MINUTES - Total runtime (default: 1440 = 24h)
  • PER_RUN_TIMEOUT_SECONDS - Per-run timeout (default: 1200 = 20min)
  • NUM_STATEMENTS - Statements per run (default: 1000)
  • LOG_TO_STDOUT - Print fuzzer output (default: false)
  • GITHUB_TOKEN - For auto-filing issues
  • SLACK_WEBHOOK_URL - For notifications

Output Files

All output goes to simulator-output/ directory:

FileDescription
test.sqlAll executed SQL statements. Failed statements prefixed with -- FAILED:, errors with -- ERROR:
schema.jsonDatabase schema at end of run (or at failure)
test.dbTurso database file (only with --keep-files)
test-sqlite.dbSQLite database file (only with --keep-files)

Reproducing Errors

Always follow these steps

  1. Find the seed in the error output: INFO: Starting differential_fuzzer with config: SimConfig {seed: 12345,...}
  2. Re-run with that seed: cargo run --bin differential_fuzzer -- --seed 12345 --verbose --keep-files
  3. Check output files:

- simulator-output/test.sql - Find the failing statement (look for -- FAILED:) - simulator-output/schema.json - Check table structure at failure time

  1. Create a minimal reproducer

- Create reproducer in .sqltest or in .rs always load Debugging skill for reference

  1. Compare behavior manually: If needed try to compare the behaviour and produce a report in the end. Always write to a tmp file first with Edit tool to test the sql and then pass it to the binaries. # Run failing SQL against SQLite sqlite3:memory: < simulator-output/test.sql # Run against tursodb CLI tursodb:memory: < simulator-output/test.sql

Understanding Failures

Oracle Failure Types

  1. Row set mismatch - Turso returned different rows than SQLite
  2. Turso errored but SQLite succeeded - Turso rejected valid SQL
  3. SQLite errored but Turso succeeded - Turso accepted invalid SQL
  4. Schema mismatch - Tables/columns differ after DDL

Warning (non-fatal)

  • Unordered LIMIT mismatch - LIMIT without ORDER BY may return different valid rows

Key Source Files

FilePurpose
main.rsCLI parsing, entry point
runner.rsMain simulation loop, executes statements on both DBs
oracle.rsCompares Turso vs SQLite results
schema.rsIntrospects schema from both databases
memory/In-memory IO for deterministic simulation

Tracing

Set RUST_LOG for more detailed output:

RUST_LOG=debug cargo run --bin differential_fuzzer -- --seed 12345

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

39.59%
按下载量换算1,700

Claude

28.14%
按下载量换算1,208

Cursor

18.63%
按下载量换算800

Gemini CLI

9.58%
按下载量换算411

安全审计

Gen Agent Trust Hub

未通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills