discover-important-function
When given a project codebase, this skill observes the important functions in the codebase for future action.
Install / Use
npx skills add benchflow-ai/skillsbench --skill discover-important-functionInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of discover-important-function
discover-important-function scores 84/100 on our quality scale, 2101st of 4,140 Development & Engineering skills we index.
Its SKILL.md is 14 KB long, well organised into 29 sections and no code examples: a thorough specification that gives an agent plenty to work with.
With 1,813 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated about 2 months ago, so discover-important-function is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
discover-important-function compared with similar skills
All 4 of these similar skills score higher than discover-important-function; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| discover-important-function (this skill)by benchflow-ai | 84 | 1.8k | 2mo ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.4k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
Frequently asked questions
- How do I install discover-important-function?
- Run
npx skills add benchflow-ai/skillsbench --skill discover-important-function. The install tabs above show the steps for each supported agent. - Which AI agents does discover-important-function work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is discover-important-function safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is discover-important-function still maintained?
- The repository was last updated about 2 months ago, so discover-important-function is actively maintained.
Skill content
View source on GitHubname: discover-important-function description: "When given a project codebase, this skill observes the important functions in the codebase for future action."
Fuzz Target Localizer
Purpose
This skill helps an agent quickly narrow a Python repository down to a small set of high-value fuzz targets. It produces:
- A ranked list of important files
- A ranked list of important functions and methods
- A summary of existing unit tests and inferred oracles
- A final shortlist of functions-under-test (FUTs) for fuzzing, each with a structured "note to self" for follow-up actions
When to use
Use this skill when the user asks to:
- Find the best functions to fuzz in a Python package/library
- Identify parsers, decoders, validators, or boundary code that is fuzz-worthy
- Decide what to fuzz based on existing test coverage and API surface
- Produce a structured shortlist of fuzz targets with harness guidance
- Automating testing pipeline setup for a new or existing Python project.
Do not use this skill when the user primarily wants to fix a specific bug, refactor code, or implement a harness immediately (unless they explicitly ask for target selection first).
Inputs expected from the environment
The agent should assume access to:
- Repository filesystem
- Ability to read files
- Ability to run local commands (optional but recommended)
Preferred repository listing command:
- Use
treeto get a fast, high-signal view of repository structure (limit depth if needed).
If tree is not available, fall back to a recursive listing via other standard shell tooling.
Outputs
Produce result:
A report in any format with the following information: - Localize important files - Localize important functions - Summarize existing unit tests - Decide function under test for fuzzing
This file should be placed in the root of the repository as APIs.txt,
which servers as the guidelines for future fuzzing harness implementation.
Guardrails
- Prefer analysis and reporting over code changes.
- Do not modify source code unless the user explicitly requests changes.
- If running commands could be disruptive, default to read-only analysis.
- Avoid assumptions about runtime behavior; base conclusions on code and tests.
- Explicitly consider existing tests in the repo when selecting targets and deciding harness shape.
- Keep the final FUT shortlist small (typically 1–5).
Localize important files
Goal
Produce a ranked list of files that are most likely to contain fuzz-worthy logic: parsing, decoding, deserialization, validation, protocol handling, file/network boundaries, or native bindings.
Procedure
-
Build a repository map
- Start with a repository overview using
treeto identify:- Root packages and layouts (src/ layout vs flat layout)
- Test directories and configs
- Bindings/native directories
- Examples, docs, and tooling directories
- Identify packaging and metadata files such as:
- pyproject.toml
- setup.cfg
- setup.py
- Identify test configuration and entry points:
- tests/
- conftest.py
- pytest.ini
- tox.ini
- noxfile.py
- Start with a repository overview using
-
Exclude low-value areas
- Skip: virtual environments, build outputs, vendored code, documentation-only directories, examples-only directories, generated files.
-
Score files using explainable heuristics Assign a file a higher score when it matches more of these indicators:
- Public API exposure: init.py re-exports, all, api modules
- Input boundary keywords in file path or symbols: parse, load, dump, decode, encode, deserialize, serialize, validate, normalize, schema, protocol, message
- Format handlers: json, yaml, xml, csv, toml, protobuf, msgpack, pickle
- Regex-heavy or templating-heavy code
- Native boundaries: ctypes, cffi, cython, extension modules, bindings
- Central modules: high import fan-in across the package
- Test adjacency: directly imported or heavily referenced by tests
-
Rank and select
- Produce a Top-N list (default 10–30) with a short rationale per file.
Output format
For each file:
- path
- score (relative, not necessarily normalized)
- rationale (2–5 bullets)
- indicators_hit (list)
Localize important functions
Goal
From the important files, identify and rank functions or methods that are strong fuzz targets while minimizing full-body reading until needed.
Approach 1: AST-based header and docstring scan
For each localized Python file, parse it using Python’s ast module and extract only:
- Module docstring
- Function and async function headers (name, args, defaults, annotations, decorators)
- Class headers and method headers
- Docstrings for modules, classes, and functions/methods
Do not read full function bodies during the initial pass unless needed for disambiguation or final selection.
Procedure
-
Build per-file declarations via AST
- Parse the file with
ast - Enumerate:
- Top-level functions
- Classes and their methods
- Nested functions only if they are likely to be directly fuzzable via an exposed wrapper
- For each symbol, collect:
- Fully-qualified name
- Signature details (as available from AST)
- Decorators
- Docstring (if present)
- Location information (file, line range if available)
- Parse the file with
-
Generate an initial candidate set using headers and docstrings Prioritize functions/methods that:
- Accept bytes, str, file-like objects, dicts, or user-controlled payloads
- Convert between representations (raw ↔ structured)
- Perform validation, normalization, parsing, decoding, deserialization
- Touch filesystem/network/protocol boundaries
- Call into native extensions or bindings
- Clearly document strictness, schemas, formats, or error conditions
-
Use tests to refine candidate selection early
- Before reading full bodies, check if tests reference these functions/modules:
- Direct imports in tests
- Fixtures that exercise particular entry points
- Parameterizations over formats and inputs
- Down-rank candidates that are already well-covered unless they are high-risk boundaries (parsers/native bindings).
- Before reading full bodies, check if tests reference these functions/modules:
-
Confirm with targeted reading only for top candidates For the top candidates (typically 10–20), read the full function bodies and capture:
- Preconditions and assumptions
- Internal helpers called
- Error handling style and exception types
- Any obvious invariants and postconditions
- Statefulness and global dependencies
-
Rank and shortlist Rank candidates using an explainable rubric:
- Input surface and reachability
- Boundary risk (parsing/decoding/native)
- Structural complexity (from targeted reading only)
- Existing test coverage strength and breadth
- Ease of harnessing
Output format
For each function/method:
- qualname
- file
- line_range (if available)
- score (relative)
- rationale (2–6 bullets)
- dependencies (key helpers, modules, external state)
- harnessability (low/medium/high)
Approach 2: Scanning all important files yourself
For each localized Python file, read the file contents directly to extract:
- Module docstring and overall structure
- Function and async function definitions (name, args, defaults, annotations, decorators)
- Class definitions and their methods
- Full function bodies and implementation details
- Docstrings for modules, classes, and functions/methods
This approach reads complete file contents, allowing for deeper analysis at the cost of higher token usage.
Procedure
-
Read important files sequentially
- For each file from the important files list, read the full contents.
- Extract by direct inspection:
- Top-level functions and their complete implementations
- Classes and their methods with full bodies
- Nested functions if they are exposed or called by public APIs
- For each symbol, collect:
- Fully-qualified name
- Complete signature (from source text)
- Decorators
- Docstring (if present)
- Full function body
- Location information (file, approximate line range)
-
Generate an initial candidate set using full source analysis Prioritize functions/methods that:
- Accept bytes, str, file-like objects, dicts, or user-controlled payloads
- Convert between representations (raw ↔ structured)
- Perform validation, normalization, parsing, decoding, deserialization
- Touch filesystem/network/protocol boundaries
- Call into native extensions or bindings
- Contain complex control flow, loops, or recursive calls
- Handle exceptions or edge cases
- Clearly document strictness, schemas, formats, or error conditions
-
Analyze implementation details from full bodies For each candidate function, inspect the body for:
- Preconditions and assumptions (explicit checks, assertions, early returns)
- Internal helpers called and their purposes
- Error handling style and exception types raised
- Invariants and postconditions (explicit or implicit)
- Statefulness and global dependencies
- Input transformations and data flow
- Native calls or external process invocations
- Resource allocation and cleanup patterns
-
Use tests to refine candidate selection
- Check if tests reference these functions/modules:
- Direct imports in tests
- Fixtures that exercise particular entry points
- Parameterizations over formats and inputs
- Down-rank candidates that are already well-covered unless they are high-risk boundaries (parsers/native bindings).
- Note which aspects of each function are tested vs untested.
- Check if tests reference these functions/modules:
-
Rank and shortlist Rank candidates using an explainable rubric:
- Input surface and reachability
- Boundary risk (parsing/decoding/native)
- Structural complexity (from full body analysis)
- Existing test coverage strength and breadth
- Ease of harnessing
- Observable implementation risks (unsafe operations, unchecked inputs, complex state)
Output format
For each function/method:
- qualname
- file
- line_range (if available)
- score (relative)
- rationale (2–6 bullets)
- dependencies (key helpers, modules, external state)
- harnessability (low/medium/high)
- implementation_notes (key observations from body analysis)
Summarize existing unit tests
Goal
Summarize what is already tested, infer test oracles, and identify gaps that fuzzing can complement.
Hard requirement
Always inspect and incorporate existing tests in the repository when:
- Ranking functions
- Selecting FUTs
- Designing input models and oracles
- Proposing seed corpus sources
Procedure
-
Inventory tests
- Locate tests and their discovery configuration (pytest.ini, pyproject.toml, tox.ini, noxfile.py).
- Enumerate test modules and map them to source modules via imports.
- Identify shared fixtures and data factories (conftest.py, fixture files, test utilities).
-
Summarize test intent For each test module:
- What behaviors are asserted
- What inputs are used
- What exceptions are expected
- What invariants are implied
-
Infer oracles and properties Common fuzz-friendly oracles include:
- Round-trip properties
- Idempotence of normalization
- Parser consistency across equivalent inputs
- Deterministic output given deterministic input
- No-crash and no-hang for malformed inputs
-
Identify coverage gaps
- FUT candidates with no direct tests
- Input classes not covered by tests (size extremes, malformed encodings, deep nesting, edge unicode, invalid schemas)
- Code paths guarded by complex conditionals or exception handlers with no tests
Output format
- test_map: module_under_test → tests → asserted behavior
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
