Reading this blog post by Christopher Wade (@Iskuri) I think that the mentioned fuzzing of a HF reader anticollision should be quite simple to implement. No need to add it to the hf 14a sim, but a own command lik hf 14a antifuzz with like one parameter for uid length. (4,7,10), would do the trick.
I'm impressed with building the whole chain, from hardware to improving crypt1 implementation for a 8bit MCU, @Iskuri is really good.
building half a proxmark for 10$