本文へ移動
cccskills
無料GitHub で公開

verify-fix

Post-fix verification — re-scan the repo, gate on `--exploits weaponized --severity high`, recheck the specific CVE against the new installed version, write the verdict to `.vulnetix/memory.yaml`. Use when confirming a fix landed, validating a version bump did not introduce regressions, or producing a clean-scan attestation for compliance.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md4.3 KB
  • evals/evals.json3.8 KB
  • evals/trigger-eval.json1.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Fix Verification Skill

Use when

  • You just applied a fix via fix and need PASS/FAIL confirmation.
  • Validating a peer-dep upgrade chain did not introduce new vulnerabilities.
  • Producing a clean-scan attestation for a compliance bundle.
  • Pre-release: confirming all triaged P1/P2 items are resolved.
  • Setting decision status from under_investigation to fixed with audit trail.

Don't use for

  • Initial scanning — use vulnetix scan or repo-impact.
  • Applying the fix — use fix first.
  • Multi-CVE upgrade verification — use @dep-upgrade-orchestrator agent.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Run after fix (or any manual remediation) to confirm the vulnerability is gone and no regressions appeared.

Step 1: Load capabilities + memory

Read .vulnetix/capabilities.yaml and .vulnetix/memory.yaml. Find the entry for $ARGUMENTS. Capture: package, fixed_version, manifest path.

Step 2: Pre-flight

# Ensure the manifest changed since last scan
git diff --name-only HEAD~5 -- "<manifest_path>" 2>/dev/null

If no recent change to the manifest, warn the user and proceed.

Step 3: Run gated scan

vulnetix scan \
  --evaluate-sca \
  --severity high \
  --exploits weaponized \
  -o json

Capture exit code. Non-zero means a critical/high vuln with weaponized exploit signal still present.

Step 4: Targeted recheck of the specific CVE

vulnetix vdb fixes "$ARGUMENTS" -o json
vulnetix vdb vuln "$ARGUMENTS" -o json

Cross-check: does the new installed version fall outside the affected range?

Step 5: Render verdict

Fix verification: <PASS | FAIL>
Vuln: $ARGUMENTS
Package: <name>
Pre-fix version: <prev>
Post-fix version: <new>
Affected range: <range>
Within affected range now? <yes/no>
Scan gate (high+weaponized): <pass/fail>
Other regressions introduced: <count>  (list top 5 if any)

Step 6: Update memory

  • On PASS: set status: fixed, decision.choice: fix-applied, append event: fix-verified.
  • On FAIL: keep status: affected, append event: fix-verification-failed with reason.

Step 7: Follow-ups on FAIL

  • Suggest dep-resolve if version bump is blocked by a transitive constraint.
  • Suggest safe-harbor-resolver (agent) if multiple manifests conflict.

Edge cases & gotchas

  • The gated scan (scan --exploits weaponized --severity high) returns exit code 1 on findings — wrap with || true if you want to capture without aborting the surrounding shell.
  • Recheck calls vdb fixes and vdb vuln, or the vulnetix_remediation and vulnetix_vuln MCP tools. Both surfaces shape their own output, so a 2 MB advisory record arrives as the 10 KB a decision needs.
  • decision.choice: fix-applied is one of 8 closed-enum values — never write arbitrary strings; the dashboard skill renders them under "Unknown".
  • If the manifest was edited but the lockfile not regenerated (npm install was skipped), the scan reports the OLD vulnerability even though the manifest looks correct. Always run <pm> install before verify.
  • Cross-check: the affected range in the vuln response should EXCLUDE the post-fix version. If both old and new versions are in the range, the bump did not reach a safe version.
  • Memory write is single-consolidated at the end (with --disable-memory on inner CLI calls) — never run verify-fix concurrently from the same session.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する