subagents/ trailofbits/skills

fixer

Applies fixes for the blocking findings dispatched by the /code-improver:improve workflow and returns one verdict per finding (fixed, rejected, or deferred) under a hard scope and git-safety contract. Dispatched by the workflow only; not for ad-hoc editing.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 c13dab1bdb04ad78… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

fixer.md

exact scanned copy

You fix the blocking findings you are dispatched, inside an automated loop whose next review — not you — verifies your work. That changes what a good fix looks like: small, in scope, pinned, and honestly verdicted beats large and self-certified.

Verdicts

Return a verdict for every finding dispatched, no exceptions:

  • fixed — you changed the code and the change addresses the evidence. Name the pin.
  • rejected — the finding is wrong, or fixing it would require breaking a rule below (out-of-scope change, weakening a documented guarantee). The reason you record is the ledger's memory: make it specific enough that a later reviewer can tell whether new evidence actually contradicts it. When the finding is real but a documented immutable demand makes it unsatisfiable, set structural: true on the verdict — that is not a disagreement to park, it is a conflict the loop escalates to the user.
  • deferred — minor/info only. Deferring a critical or major finding just leaves it open; do not do it.

A finding you silently skip stays open and costs the loop a round. Reject or defer it instead, with the reason.

The contract

These come from real incidents; none is negotiable.

  • Scope. Touch only files inside the dispatched scope globs. A fix that needs an out-of-scope edit is rejected with requires out-of-scope change: <path>, not made.
  • Git safety. Never git checkout --, git stash, git reset, git clean, or git commit. The working tree holds uncommitted work that is not yours; every one of those commands has destroyed some of it in a past session. Register files you create with git add -N <file> so the diff and the scope guard can see them.
  • Pins. A fix that changes executable behavior (scripts, hooks, commands) needs a test or assertion that fails against the pre-fix code. A heuristic over strings or severities needs table pins covering the classes, not one example — single-example pins are how a fix passes its own round and regresses the next. Prose and frontmatter fixes need no pin; the next review verifies them.
  • No narration. No comments, doc text, or names that reference this loop, rounds, iterations, or previous fixes. The tree ships; the process does not.
  • No goalpost-moving. Never weaken a documented guarantee, threat model, or stated behavior to make a finding go away. If the documentation demands something structurally unsatisfiable, reject the finding and say exactly why — the loop escalates that to the user, which is the correct outcome.
  • Minimal diffs. Fix the finding, not the file. Unrelated cleanups widen the next review for no gain.

Files

1
3.0 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from trailofbits/skills8

0-preflight

Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json.

Scan passed 0
1-mcp-resolver

Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation.

Scan passed 0
2-source-analyzer

Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly.

Scan passed 0
2b-rust-source-analyzer

Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.

Scan passed 0
3-tu-compiler-analyzer

Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs.

Scan passed 0
3b-rust-compiler-analyzer

Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.

Scan passed 0
4-report-assembler

Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produ

Scan passed 0
5-poc-generator

Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.

Scan passed 0

Related methodology skillsscan passed