AgentStack
SKILL verified MIT Self-run

Fix Selected Security Findings

skill-edmund-xl-ai-security-audit-playbook-fix-selected-security-findings · by edmund-xl

Use this skill only when the user explicitly selects security finding IDs to fix. Do not use it to fix all findings or perform broad refactors.

No reviews yet
0 installs
19 views
0.0% view→install

Install

$ agentstack add skill-edmund-xl-ai-security-audit-playbook-fix-selected-security-findings

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Fix Selected Security Findings? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

fix-selected-security-findings

English

Purpose

Fix explicitly selected security findings.

Required input

  • Finding IDs
  • Audit report or finding details
  • Expected scope
  • Test framework

Workflow

  1. Confirm selected finding IDs.
  2. Locate minimal patch.
  3. Add regression tests.
  4. Run targeted tests if allowed.
  5. Summarize changes and risks.
  6. Do not commit unless explicitly requested.

Safety rules

Do not fix unselected findings. Do not broaden privileges. Do not make broad refactors.

Canonical finding format

id: F-001
severity: Critical | High | Medium | Low | Informational
confidence: High | Medium | Low
category:
affected_code:
root_cause:
exploit_path:
preconditions:
impact:
evidence:
minimal_fix:
regression_test:
auto_fix_suitability: Safe | Needs Human Review | Do Not Auto-Fix
notes:

v0.6 operational guardrails

  • Keep the skill within its stated trigger conditions and the user's explicitly provided scope.
  • Preserve project safety boundaries: audit-only by default; Do not execute exploits, Do not auto-merge, Do not upload private source code or secrets, and do not scan unrelated repositories without explicit user request.
  • Ask for explicit human approval before patching high-risk auth, IAM, governance, funds, terminal, or agent-tooling behavior.
  • Report validation performed, files changed, residual risk, and any skipped future-phase work when finished.

中文

目的

使用这个 skill 进行修复已选择的安全 finding。它应该帮助审查者把输入边界、风险证据、影响、修复建议和回归测试组织成可复核的安全输出。

触发条件

适用于 用户明确指定 finding ID 且授权进行最小修复的场景。如果请求超出这些边界,先说明范围差异,并选择更合适的 prompt、skill 或人工 review 路径。

不适用场景

不要用于自动修复所有 finding、无边界重构、未授权提交或高风险改动直接落地。不要把这个 skill 当作自动扫描整个仓库、执行 exploit、上传私有源码或 secrets、自动提交、自动推送或 auto-merge 的许可。

操作流程

  1. 明确用户给出的目标、允许查看的材料和不能触碰的范围。
  2. 收集必要上下文,但只读取完成任务所需的文件、diff、workflow、fixture 或文档。
  3. 识别 trust boundary、privileged operation、sensitive data、preconditions 和 security impact。
  4. 只报告有 evidence 的 finding;缺少上下文时写 question 或 assumption。
  5. 为 confirmed issue 提出 minimal fix,并规划修复前失败、修复后通过的最小回归测试,以及合法路径保持可用的测试。
  6. 完成后报告验证输出、残余风险和需要人工确认的事项。

安全规则

默认 audit-only。未经明确授权,不 patch、不 commit、不 push、不创建 PR、不 merge。不要执行 exploit,不要访问生产系统,不要打印 secrets。涉及 IAM、authz 模型、资金、治理、terminal 执行或 agent-tooling 权限的修复必须进入人工 review。

输出要求

使用 canonical finding format。每个 finding 都要包含 severity、confidence、category、affectedcode、rootcause、exploitpath、preconditions、impact、evidence、minimalfix、regressiontest、autofix_suitability 和 notes。

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.