Fuzz Crash Handoff is a reusable Skill for turning supplied fuzzer or AI security-agent crash artifacts into a reviewable triage packet. It preserves candidate identity, groups likely duplicates with an explicit basis, separates observations from automated claims, and defines the evidence required before root-cause, remediation, or disclosure decisions.
- Security engineers receiving crash reports from automated campaigns.
- Maintainers who need reproducible evidence before accepting a vulnerability finding.
- Fuzzing teams consolidating sanitizer logs, stack hashes, inputs, and build provenance.
- Reviewers validating AI-generated severity, exploitability, or patch suggestions.
- Consolidate a batch of ASan, UBSan, signal, or timeout observations.
- Cluster likely duplicate crashes without losing individual regression inputs.
- Identify which reports are ready for root-cause work and which need reproduction.
- Convert agent labels into traceable claims rather than unsupported facts.
- Prepare a staged validation handoff for maintainers and security reviewers.
- Four evidence classes: observed, derived, agent claim, and unknown.
- Three intake verdicts and explicit per-candidate evidence states.
- Duplicate clustering with representative, basis, confidence, conflicts, and member retention.
- Campaign provenance and missing-artifact inventory.
- Ordered Reproduction, Minimization, Root-cause, Remediation, Regression, and Disclosure review stages.
- Status-change gates that name the required evidence and reviewer.
- A fixed advisory boundary that prevents crash evidence from becoming an unsupported exploitability claim.
- Collect the campaign identifier, target revision, harness, build, instrumentation, corpus snapshot, environment, and timestamps.
- Supply each candidate ID, input, exact reproduction procedure when known, attempt count, diagnostics, stack evidence, and agent-generated labels.
- Ask the agent to use Fuzz Crash Handoff and provide only the supplied packet.
- Review the intake verdict, provenance gaps, candidate inventory, and likely-duplicate clusters.
- Assign owners to the ordered validation stages and stop when a required artifact is unavailable.
- Update candidate states only after the named evidence and human review are complete.
- Save the Markdown handoff beside the immutable crash inputs and campaign logs.
- iPolloWork 0.50.12 or later for the packaged import path verified here.
- A local project using the OpenCode engine.
- Crash evidence supplied as text or files; no external account is required.
- An isolated environment is required if maintainers later execute untrusted inputs. This Skill does not run them.
Inputs:
- campaign and target provenance;
- candidate IDs and immutable input references;
- exact commands or procedures when available;
- attempt counts, exit states, sanitizer logs, stacks, and hashes;
- agent classifications or patch suggestions;
- known fixes and regression evidence, when available.
Output:
- an overall intake decision;
- campaign provenance and missing evidence;
- per-candidate evidence state and next action;
- likely-duplicate clusters with confidence and retained identities;
- an evidence ledger separating facts, derivations, claims, and unknowns;
- a staged validation plan and status-change gates;
- unresolved inputs and a fixed security advisory boundary.
The example packet contains two repeatable ASan heap-buffer-overflow observations with the same normalized stack hash and one signal-only observation labelled “critical RCE” by an automated agent.
Invoke:
Use Fuzz Crash Handoff to triage examples/crash-packet.md. Preserve every candidate ID, do not run code, and save the report as Markdown.
Expected result: actionable-with-gaps. The first two candidates form one likely-duplicate cluster while retaining both inputs. The signal-only candidate remains unclustered and needs reproduction. The automated RCE label stays an agent claim; security impact and exploitability remain unknown. See expected handoff.
- Download
fuzz-crash-handoff-1.0.0.ipollowork-pluginfrom the GitHub Release. - Open Extensions → Plugins → Add → File in iPolloWork.
- Select the package and confirm publisher
sykdhqk, version1.0.0, and one Skill resource. - Install the plugin and confirm Fuzz Crash Handoff and its Skill toggle are enabled.
- Open a local OpenCode project and attach or paste a crash packet.
- Explicitly ask the agent to use Fuzz Crash Handoff. Confirm it loads
SKILL.md,triage-rules.md, andreport-format.md. - Save the Markdown handoff with the campaign evidence.
For standalone import, unzip fuzz-crash-handoff-1.0.0-skill.zip and choose the contained fuzz-crash-handoff folder from the local Skill import screen.
If the package is rejected, confirm that the file was downloaded completely, the extension is .ipollowork-plugin, the app meets the declared version floor, and an older package with the same ID is not masking the new version.
Node.js 22 plus the standard zip, unzip, and shasum commands are sufficient:
npm run package
npm test
cd dist
shasum -a 256 -c SHA256SUMS.txtThe build creates a direct iPolloWork installer, standalone Skill ZIP, source ZIP, and checksum manifest. The installer contains one schemaVersion 2 manifest and the complete Skill directory.
No. It only organizes supplied evidence and proposes bounded procedures. Run untrusted inputs later in an isolated environment under the responsible team’s controls.
No. It supports a likely-duplicate cluster. A reviewed failing invariant and fix coverage are needed to confirm root-cause identity.
No. The Skill does not confirm vulnerability status, severity, exploitability, or disclosure readiness. Those require root-cause, attacker-control, impact, and human-review evidence.
No. It remains an agent claim until independent evidence supports the impact.
Version 1.0.0 is designed as an untrusted declarative package with no permissions, local service, executable hook, custom authorization, or MCP resource. Desktop acceptance records the actual import and invocation environment in desktop acceptance.
Validated scope covers package structure, Skill discovery, reference loading, and one supplied-packet handoff. It does not run fuzzers, execute crash inputs, validate a patch, prove root cause, confirm exploitability, or authorize disclosure.
MIT