skills/openai/plugins/fix-finding/Gen Agent Trust Hub

fix-finding

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • Structured Remediation Workflow: The skill defines a methodical process for security patching, encompassing reproduction, tactical strategy selection, implementation, and multi-stage verification. This structured approach helps ensure that security fixes are both effective and minimal.
  • Rigorous Verification Gates: The instructions mandate several specific verification steps—including buildability checks, security closure (re-running exploit triggers), bypass reviews, and repository-level tests. These gates act as a safeguard to confirm the vulnerability is closed without introducing side effects.
  • Evidence-Based Validation: The skill requires establishing concrete reachability and reproducing the issue before applying a fix. By demanding failing tests or fail-states as a prerequisite for a patch, it reduces the risk of incorrect modifications based on generic or unproven security labels.
  • Controlled Command Execution: The skill involves executing repository-native setup and validation commands. While this includes shell interactions, the instructions explicitly limit these to supported repository commands and focused verification tasks, consistent with standard developer environment operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:46 AM
Security Audit — agent-trust-hub — fix-finding