Skip to main content
NEW · APP STORE Now on iOS · macOS · iPad Android & Windows soon GET IT
Prompts Security Audit Fix Commit Reviewer

agent security skill risk: medium

Security Audit Fix Commit Reviewer

The prompt instructs the model to verify that fix commits properly address audit findings without introducing new bugs or vulnerabilities, by reviewing commits against original fin…

  • Policy sensitive
  • Human review

SKILL 1 file

SKILL.md
---
name: fix-review
description: "Verify fix commits address audit findings without new bugs"
---
# Fix Review

## Overview

Verify that fix commits properly address audit findings without introducing new bugs or security vulnerabilities.

## When to Use This Skill

Use this skill when you need to verify fix commits address audit findings without new bugs.

Use this skill when:
- Reviewing commits that address security audit findings
- Verifying that fixes don't introduce new vulnerabilities
- Ensuring code changes properly resolve identified issues
- Validating that remediation efforts are complete and correct

## Instructions

This skill helps verify that fix commits properly address audit findings:

1. **Review Fix Commits**: Analyze commits that claim to fix audit findings
2. **Verify Resolution**: Ensure the original issue is properly addressed
3. **Check for Regressions**: Verify no new bugs or vulnerabilities are introduced
4. **Validate Completeness**: Ensure all aspects of the finding are resolved

## Review Process

When reviewing fix commits:

1. Compare the fix against the original audit finding
2. Verify the fix addresses the root cause, not just symptoms
3. Check for potential side effects or new issues
4. Validate that tests cover the fixed scenario
5. Ensure no similar vulnerabilities exist elsewhere

## Best Practices

- Review fixes in context of the full codebase
- Verify test coverage for the fixed issue
- Check for similar patterns that might need fixing
- Ensure fixes follow security best practices
- Document the resolution approach

## Resources

For more information, see the [source repository](https://github.com/trailofbits/skills/tree/main/plugins/fix-review).

## Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

REQUIRED CONTEXT

  • fix commits
  • original audit finding

OPTIONAL CONTEXT

  • full codebase
  • test coverage

ROLES & RULES

  1. Use this skill only when the task clearly matches the scope described above.
  2. Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  3. Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

EXPECTED OUTPUT

Format
plain_text
Constraints
  • document the resolution approach
  • verify test coverage

SUCCESS CRITERIA

  • Verify that fix commits properly address audit findings without introducing new bugs or security vulnerabilities
  • Ensure the original issue is properly addressed
  • Verify no new bugs or vulnerabilities are introduced
  • Ensure all aspects of the finding are resolved

CAVEATS

Missing context
  • Input format or placeholders for audit findings and commit details
  • Output format or template for verification results
Ambiguities
  • Does not specify desired output format or structure for the review results.

QUALITY

OVERALL
0.65
CLARITY
0.80
SPECIFICITY
0.55
REUSABILITY
0.65
COMPLETENESS
0.60

IMPROVEMENT SUGGESTIONS

  • Add an 'Inputs' section with placeholders for audit report excerpts and commit diffs.
  • Define a required output structure (e.g., sections for resolution status, regression risks, test coverage).

USAGE

Copy the prompt above and paste it into your AI of choice — Claude, ChatGPT, Gemini, or anywhere else you're working. Replace any placeholder sections with your own context, then ask for the output.

MORE FOR AGENT