本文へ移動
cccskills
無料GitHub で公開

fix-security-issue

Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Fix Security Issue

Use this skill after an authorized review-security-issue review identifies an actionable concern. Follow SECURITY.md; do not disclose vulnerability details in a public issue. A direct user request to fix a specific reviewed issue authorizes implementation. For unattended work, inspect current state:* label descriptions, maintainer assignments, and comments to verify that remediation is authorized. Do not infer approval from a state that only records technical validation.

  1. Fetch the issue and its comments with gh issue view <id> --json number,title,body,state,labels,comments. Follow Label Discovery in CONTRIBUTING.md and confirm this is a security issue; resolve unclear meanings before interpreting authorization. Find the review marked > **🔒 security-review-agent** and its remediation plan. If the review is missing or found the issue not actionable, stop and report that result.
  2. Verify the review against current code. Adapt the plan when code has changed, and record material deviations. Check for an existing owner, branch, or PR.
  3. Create a fix branch or worktree following Branch Names in CONTRIBUTING.md, preserving unrelated changes and disclosure boundaries. Implement the smallest safe fix and add regression tests for the security boundary. Avoid logging secrets or adding public exploit detail.
  4. Follow the verification guidance in CONTRIBUTING.md. Run format, lint, compile or type checks, and regression tests for the affected security boundary and dependent components, plus the relevant E2E lane for sandbox or policy changes. Broaden verification when the fix spans components or a concrete risk remains; do not require unaffected Rust or SDK suites solely to create a signed-off commit or PR.
  5. Follow create-github-pr and use Closes #<id> for the reviewed issue. Every PR from this issue-backed remediation workflow must close its own issue; split multi-PR remediations into separate issues in the authorized security workflow. Keep the PR description appropriately scoped to its disclosure venue.

Begin any fix comments with > **🔧 security-fix-agent**. Do not change human disposition or introduce agent:* workflow labels.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Plan and implement work described in a GitHub issue, including verification, documentation, and a PR that closes the issue.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64. Use when working on Windows compilation, `windows:*` mise tasks, unsupported Windows compute-driver contracts, or Windows build reports. This skill does not implement Docker, Kubernetes, Podman, VM, MXC driver, policy translation, MSI, service, or supervisor runtime support on Windows.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

Create GitHub issues using the gh CLI. Use when the user wants to create a new issue, report a bug, request a feature, or create a task in GitHub. Trigger keywords - create issue, new issue, file bug, report bug, feature request, github issue.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

Create GitHub pull requests using the gh CLI. Use when the user wants to create a new PR, submit code for review, or open a pull request. Trigger keywords - create PR, pull request, new PR, submit for review, code review.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

Create OpenShell RFC proposals in rfc/ from a design request. Use when the user asks to write, draft, start, create, or update an RFC, Request for Comments, architecture proposal, API proposal, process proposal, or cross-cutting design proposal that should follow the OpenShell RFC process and template.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

Investigate an OpenShell problem and create a structured issue with technical findings for human disposition.

日本語の概要は準備中です。原文の説明を表示しています。

NVIDIA/OpenShell1.6万2026年10月10日 更新

NVIDIA のスキルをすべて見る

このスキルの問題を報告する