About Crucible¶
Who¶
Crucible is built and maintained by Halo Forge Labs. It started as a focused effort to answer a simple question: what happens when you point a structure-aware fuzzer at the binary parsers that every ML inference stack depends on?
What Crucible Is¶
A structure-aware fuzzer for the code that turns an untrusted model file into a running model. That path runs through two stages, and Crucible targets both:
- Load time: The hand-written parsers and loaders that read a file's structure: GGUF, ONNX, SafeTensors, and TensorFlow Lite headers, metadata, tensor info, and offsets, across llama.cpp, Ollama, whisper.cpp, stable-diffusion.cpp, ONNX Runtime, and more.
- Run time: The quantization and compute kernels that execute after the file parses. Quantization metadata (group sizes, block sizes, scale and zero-point shapes, group indices) flows straight into kernel pointer arithmetic, a surface that up-front file verification does not cover.
Other targets across the ecosystem include the ggml-rpc wire protocol, GBNF grammars, Jinja chat templates, JSON Schema constraints, and framework loaders (PyTorch/TorchScript, mistral.rs, tract).
Crucible combines format-aware mutation, native harnesses, explicit execution observation, Exact and Stable crash identities, stateful protocol testing, and capability-preservation checks. Generated reports are unrated investigation records: the workflow requires replay on a clean pinned build, source inspection, operator severity ratification, and a human disclosure decision before a new observation becomes a filing.
What Ships¶
The public tool is three binaries, produced by make build: crucible, crucible-gen and crucible-triage. The CLI reference is generated against those binaries, and a documentation check rejects any example that passes a flag they do not accept.
The repository also holds developer-only tooling, experiment drivers and work in progress. Those are not part of the public tool, and the documentation does not describe them as if they were.
What Crucible Is Not¶
- Not a model-level attack tool. Crucible does not do adversarial examples, prompt injection, model extraction, or training data poisoning. Those are important research areas, but they are outside this project's scope.
- Not a replacement for generic fuzzers. Crucible uses AFL++ and libFuzzer as execution backends and adds format-aware mutation. Byte mutation remains valuable for framing and error paths; structure-aware mutation targets relationships byte mutation does not express directly.
- Not a production attack tool. The CLI finds bugs and generates reproducer files. Research may pursue the demonstrated impact in an authorized lab, but Crucible does not automate attacks against production systems.
Disclosure Policy¶
Potential vulnerabilities discovered by Crucible are handled through responsible disclosure; whether, where, and when to file remains an operator decision:
- Validate: Reproduce the issue, read the source, establish the primitive, and bind the evidence to the tested build
- Coordinate: Use the project's current private channel or an appropriate coordinator
- Remediate: Verify any proposed fix against the invariant and genuine artifacts
- Publish: Follow the agreed coordination plan and preserve corrections and provenance
Crucible does not automate publication or disclosure. See the Responsible Disclosure guide for the full workflow.
Contact¶
- GitHub: professor-moody/crucible
- Security issues: Use GitHub Security Advisories for any security concerns about Crucible itself