fix-finding Skill
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. Published by openai in plugins.
Decision snapshot
Is this a fit?
Security review, Includes SKILL.md, Reusable instructions
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
18 days ago
No specific cautions were detected. Review the source and requested permissions before installing.
What is fix-finding Skill?
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans. Published by openai in plugins. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Security review use cases
Declared skill metadata
- Source file: plugins/codex-security/skills/fix-finding/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use fix-finding Skill
- Use it for security review.
Built with
Editorial notes
Source
- Creator: openai
- Repository: openai/plugins
- Skill file: plugins/codex-security/skills/fix-finding/SKILL.md
What it does
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Skill instructions
Fix Finding Objective Turn a current security finding into a minimal, validated code change. If the code is already safe, prove that and report that no change was needed. Judge the result in this order: 1. the current state is correctly classified as vulnerable, already safe, or unproven 2. any fix completely closes the broken security boundary 3. legitimate behavior and compatibility are preserved 4. relevant repository checks pass 5. the implementation follows repository conventions 6. the patch contains only the scope necessary for the earlier properties Never trade an earlier property for a later one. Minimal means the smallest repository-native change that satisfies all earlier properties, not the fewest lines. Patch Contract Before editing, establish from repository evidence: - affected component and current source-to-sink path or broken control - attacker-controlled input and required preconditions - security invariant and narrowest plausible enforcement boundary - legitimate be
Verified compatibility and discovery
Frequently asked questions
What is fix-finding?
fix-finding is a open-source AI agent skill with Copy skill directory. Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Who is fix-finding best for?
fix-finding is best for reusing agent instructions, scripts, and references, security review workflows.
How do I install fix-finding?
Install or run fix-finding using Copy skill directory. Check fix-finding for the latest setup command.
Is fix-finding actively maintained?
fix-finding may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.