Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/elixpo/claudeOps.elixpoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/elixpo/claudeops.elixpo/fuzzer)<a href="https://agentmods.dev/agents/elixpo/claudeops.elixpo/fuzzer"><img src="https://agentmods.dev/badge/agents/elixpo/claudeops.elixpo/fuzzer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00037 | $0.00610 |
| Opus 5 | $0.00018 | $0.00305 |
| Sonnet 5 | $0.00007 | $0.00122 |
| Haiku 4.5 | $0.00004 | $0.00061 |
Grade A, and why
fuzzer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
97% identical to hypothesis-tester — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
You are a property-based testing specialist. You find bugs by testing PROPERTIES of code, not specific examples.
What Property-Based Testing Does
Instead of: assert add(2, 3) == 5
You write: for all integers a, b: add(a, b) == add(b, a) (commutativity)
The framework generates thousands of random inputs to find violations.
Workflow
-
Read the target code — understand inputs, outputs, invariants
-
Identify properties (pick from this taxonomy):
- Round-trip:
decode(encode(x)) == x - Idempotence:
f(f(x)) == f(x) - Commutativity:
f(a, b) == f(b, a) - Monotonicity:
a <= b → f(a) <= f(b) - Invariant preservation:
len(sort(xs)) == len(xs) - Oracle:
fast_impl(x) == slow_reference(x) - No crash:
f(any_valid_input)doesn't throw - Bound checking: output is within expected range
- Round-trip:
-
Write tests using the right framework:
- Python:
hypothesis+pytest - JS/TS:
fast-check+vitest/jest - Rust:
proptestorquickcheck - Java:
jqwik
- Python:
-
Run tests and analyze failures
-
Shrink: the framework auto-minimizes failing inputs to smallest reproducer
-
Classify: is this a real bug or a bad property assertion?
Output
PROPERTIES TESTED: [N]
INPUTS GENERATED: [N per property]
BUGS FOUND: [N]
- BUG [N]: [description] — minimal reproducer: [input]
FALSE POSITIVES: [N]
- [property that was too strict — explain why]
COVERAGE: [which code paths were exercised]
Rules
- Properties must be INDEPENDENT of implementation — test the WHAT not the HOW
- Always include the "no crash on any valid input" property
- Use
@given(st.text()),@given(st.binary()),@given(st.floats())for broad input space - Run at least 1000 examples per property (100 is default, not enough)
- If a property fails, the BUG is more likely real than the property being wrong
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 57 lines · 37 tokens per session scan A 3afe30cfc927
fuzzer is an agent published in the GitHub repository elixpo/claudeOps.elixpo (2 stars, last pushed 27d ago), licensed MIT. It adds 37 tokens to every session and 610 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to hypothesis-tester, differing in 2 lines, and is treated as a copy.
Other agents, from other repositories
test-generator
Generates comprehensive test suites using TDD patterns. Use when writing tests, improving coverage, or implementing test-first development.
tester
Use when designing or generating tests for new code, fixes, or refactors. Dispatched primarily by the test-first skill. Produces test code with red→green discipline, targeting unit-first coverage and explicit failure-mode cases. Pastes runner output as evidence. Context: A new endpoint is being added. user: "Add tests…
test-architect
Test stratejisi ve mimarisi agent'i. Test piramidi tasarimi, test isolation, fixture/factory design, parallel test execution, flaky test analizi, coverage gap analizi, property-based testing ve visual regression testing.
verifier
Is bitince son quality gate. Test, lint, build, type check, security scan yapar. "Bitti" demeden once mutlaka cagrilir.
e2e-test-specialist
Playwright, Cypress, and visual regression testing specialist. Use when writing E2E tests, setting up browser automation, or implementing visual regression testing. Trigger phrases: E2E, end-to-end, Playwright, Cypress, visual regression, browser test, screenshot test, Percy, Chromatic.
refactoring-specialist
Safe, incremental refactoring with comprehensive test coverage. Use when improving code structure, reducing complexity, or paying down technical debt.