Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis
.claude/skills/ffuf-web-fuzzing/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 197% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 363% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 132% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 171% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 645% | 0% |
> ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited.
> Mandatory confirmation gate > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
Read the detailed guide before executing this skill. It retains the complete procedure and reference material. Treat its safety, prerequisites, and validation requirements as mandatory. For focused work, load the relevant sections; for end-to-end work, read the guide completely.
ffuf during authorized security testing or penetration testing.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 13,291 | 8,390 | -37% | 1 | 1 | 0% | 2,431 | 7,229 | +197% | 0 | 0 | — |
case-02 | fail→pass | 9,257 | 9,365 | +1% | 1 | 1 | 0% | 1,596 | 7,389 | +363% | 0 | 0 | — |
case-03 | pass→pass | 22,929 | 10,693 | -53% | 1 | 1 | 0% | 2,819 | 7,636 | +171% | 0 | 0 | — |
case-04 | pass→pass | 56,467 | 6,840 | -88% | 1 | 1 | 0% | 845 | 6,299 | +645% | 0 | 0 | — |
case-05 | pass→pass | 7,577 | 5,925 | -22% | 1 | 1 | 0% | 1,337 | 6,794 | +408% | 0 | 0 | — |
case-06 | pass→pass | 7,721 | 5,145 | -33% | 1 | 1 | 0% | 1,540 | 6,707 | +336% | 0 | 0 | — |
case-07 | pass→pass | 4,358 | 4,417 | +1% | 1 | 1 | 0% | 769 | 6,175 | +703% | 0 | 0 | — |
case-08 | pass→pass | 6,745 | 18,868 | +180% | 1 | 1 | 0% | 1,252 | 6,326 | +405% | 0 | 0 | — |
case-09 | pass→pass | 6,832 | 3,385 | -50% | 1 | 1 | 0% | 1,372 | 6,310 | +360% | 0 | 0 | — |
case-10 | pass→pass | 9,137 | 3,089 | -66% | 1 | 1 | 0% | 1,416 | 6,126 | +333% | 0 | 0 | — |
case-11 | pass→pass | 6,626 | 2,996 | -55% | 1 | 1 | 0% | 1,124 | 6,215 | +453% | 0 | 0 | — |
case-12 | pass→pass | 4,218 | 3,351 | -21% | 1 | 1 | 0% | 719 | 6,268 | +772% | 0 | 0 | — |
case-13 | pass→pass | 4,610 | 4,133 | -10% | 1 | 1 | 0% | 786 | 6,362 | +709% | 0 | 0 | — |
case-14 | pass→pass | 6,038 | 3,222 | -47% | 1 | 1 | 0% | 1,131 | 6,209 | +449% | 0 | 0 | — |
case-15 | pass→pass | 7,770 | 5,323 | -31% | 1 | 1 | 0% | 1,264 | 6,629 | +424% | 0 | 0 | — |
case-16 | fail→pass | 15,670 | 4,127 | -74% | 1 | 1 | 0% | 2,777 | 6,445 | +132% | 0 | 0 | — |
case-17 | pass→pass | 2,112 | 3,012 | +43% | 1 | 1 | 0% | 360 | 6,186 | +1618% | 0 | 0 | — |
case-18 | pass→pass | 5,617 | 4,632 | -18% | 1 | 1 | 0% | 1,011 | 6,392 | +532% | 0 | 0 | — |
case-19 | pass→pass | 3,504 | 3,408 | -3% | 1 | 1 | 0% | 514 | 6,227 | +1111% | 0 | 0 | — |
case-20 | pass→pass | 6,520 | 5,183 | -21% | 1 | 1 | 0% | 1,180 | 6,588 | +458% | 0 | 0 | — |
case-21 | pass→pass | 16,557 | 9,673 | -42% | 1 | 1 | 0% | 3,555 | 7,785 | +119% | 0 | 0 | — |
case-22 | pass→pass | 10,638 | 8,598 | -19% | 1 | 1 | 0% | 2,231 | 7,567 | +239% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v2, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 7/28/2026 | +32% |
Other measured skills in the registry, with their headline benchmark lift.