krait-fuzz

krait-fuzz is a command for Claude Code from ZealynxSecurity/krait. It costs 0 tokens per session (1,101 once invoked), scanned A, original, MIT.

A command that checks smart-contract code by turning its expected rules into Foundry tests. Foundry is a toolkit for building and testing Ethereum smart contracts.

In plain words
What is it for?
Use it to read a contract project, write invariant-based fuzz tests, run them with Forge, fix test issues, and report whether the stated rules hold.
Why use it?
It helps check whether important rules continue to hold across many automatically generated inputs. It also separates a broken test from a genuine rule violation.

Command for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/zealynxsecurity/krait/krait-fuzz
Clone the repo
git clone --depth 1 https://github.com/ZealynxSecurity/krait

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for krait-fuzz

README.md
[![agentmods](https://agentmods.dev/badge/commands/zealynxsecurity/krait/krait-fuzz.svg)](https://agentmods.dev/commands/zealynxsecurity/krait/krait-fuzz)
Your own site
<a href="https://agentmods.dev/commands/zealynxsecurity/krait/krait-fuzz"><img src="https://agentmods.dev/badge/commands/zealynxsecurity/krait/krait-fuzz.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,101 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01101
Opus 5 $0.00000 $0.00550
Sonnet 5 $0.00000 $0.00220
Haiku 4.5 $0.00000 $0.00110

Measured 5d ago against content hash 8ab493787693, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

krait-fuzz scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/krait-fuzz.md · 123 lines

How it starts

The opening of the file, as written. The whole thing — 123 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Krait Fuzz — Invariant-Based Fuzzing

Run an invariant-based fuzzing campaign: Understand → Extract Invariants → Generate Foundry Tests → Run & Fix Iteratively → Report.

Usage

/krait-fuzz                    # Fuzz current directory
/krait-fuzz src/contracts/     # Fuzz specific directory

Instructions

You are Krait's invariant fuzzer. Your job is NOT to find bugs directly — instead, you understand the code, document its invariants, generate Foundry fuzzing tests, run them, and iteratively fix the tests until the invariants are conclusively verified or violated.

CRITICAL RULES:

  • You are NOT an auditor. Do NOT look for vulnerabilities. Focus on understanding the code and extracting invariants.
  • Read EVERY source file. Never assume what code does from its name.
  • Every invariant MUST have a formal expression when possible.
  • Generated tests must compile and run with forge test.
  • When a test fails, determine if it's a test bug or a real invariant violation BEFORE reporting.

Phase 0: RECON

Goal: Understand the protocol before extracting invariants.

Read and follow: ~/.claude/skills/krait/recon/SKILL.md — contains the recon methodology.

Key steps:

  1. Create .audit/ and .audit/invariant-tests/ directories
  2. Read README, docs, config files
  3. Understand the protocol: what it does, how funds flow, what roles exist
  4. Map contract relationships, inheritance, imports
  5. Identify the Foundry setup: foundry.toml, remappings.txt, compiler version

Phase 1: INVARIANT EXTRACTION

Goal: Document every property that must always hold.

Read and follow: ~/.claude/skills/krait/fuzzer/SKILL.md

How to extract invariants:

  1. Read state variables — what relationships exist between them?
  2. Read require/assert statements — these are explicit invariant checks
  3. Trace state-changing functions — what must be true before and after?
  4. Look for accounting identities: totalSupply == sum(balances), conservation laws
  5. Check access control: which functions are restricted?
  6. Identify state machine constraints: valid states and transitions
  7. Find economic invariants: exchange rates, price bounds, fee calculations
  8. Cross-contract: do relationships hold across contract boundaries?

Read the full file on GitHub · 123 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 123 lines · 0 tokens per session scan A 8ab493787693

Subscribe to this mod's changes

krait-fuzz is a command published in the GitHub repository ZealynxSecurity/krait (22 stars, last pushed 25d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,101 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.