Agent Skillsopenai/codex-security › verify-fix

verify-fix

GitHub

用于验证现有安全修复是否真正解决了原始漏洞,仅进行只读检查,不修改代码或提交变更。

sdk/typescript/_bundled_plugin/skills/verify-fix/SKILL.md openai/codex-security

触发场景

用户询问某个安全补丁是否有效 需要确认已知漏洞已被修复

安装

npx skills add openai/codex-security --skill verify-fix -g -y
更多选项

非标准路径

npx skills add https://github.com/openai/codex-security/tree/main/sdk/typescript/_bundled_plugin/skills/verify-fix -g -y

不安装直接使用

npx skills use openai/codex-security@verify-fix

指定 Agent (Claude Code)

npx skills add openai/codex-security --skill verify-fix -a claude-code -g -y

安装 repo 全部 skill

npx skills add openai/codex-security --all -g -y

预览 repo 内 skill

npx skills add openai/codex-security --list

SKILL.md

Frontmatter
{
    "name": "verify-fix",
    "description": "Use when the user asks whether an existing security fix, patch, finding, or completed issue actually remediates the original vulnerability without modifying the repository. Do not use to validate candidate findings, implement patches, or run full repository scans."
}

Verify Fix

Objective

Determine whether each supplied security finding has been fixed in the current checkout. Operate in standalone verification-only mode; do not create, modify, or delete repository files, apply patches, commit changes, write artifacts, or modify issue trackers.

Assessment Method

Use ../../references/static-finding-assessment.md to identify the original attacker-controlled source, security control, sensitive sink, reachable path, trust boundary, counterevidence, and proof gaps. If the caller already supplied that reference in the prompt, use the supplied contents without reading it again.

Verification Workflow

  1. Establish the original vulnerability, its preconditions, affected security boundary, and legitimate behavior that must continue to work.
  2. Confirm the current checkout contains the affected component. Follow moved or refactored code rather than treating a missing file, removed line, or changed function name as proof of remediation.
  3. Trace the original exploit path through the current implementation and check the nearest relevant control, equivalent paths, and plausible bypasses.
  4. Run the original reproducer, focused regression checks, or legitimate-behavior checks only when they can run without modifying the repository. Preserve exact static evidence when runtime checks are unavailable.
  5. Return one result per supplied finding, in the requested order. Treat closed tickets, unrelated passing tests, and the absence of a new scan finding as insufficient proof.

Result Contract

Return exactly one JSON object:

{
  "results": [
    {
      "id": "finding-or-issue-id",
      "status": "fixed|still_vulnerable|inconclusive",
      "evidence": "specific current source, exploit, test, or proof-gap evidence"
    }
  ]
}
  • Use fixed only when evidence proves the original security boundary is closed and legitimate behavior remains intact.
  • Use still_vulnerable only when evidence proves the original vulnerable path remains reachable.
  • Use inconclusive for a repository mismatch, missing original context, unavailable relevant checks, an unproven legitimate control, or another material proof gap.

Never infer a stronger verdict by weakening the read-only boundary, substituting a different vulnerability, or hiding missing evidence.

版本历史

  • 5210198 当前 2026-08-27 10:07

同 Skill 集合

sdk/typescript/_bundled_plugin/skills/assess-patch-risk/SKILL.md
sdk/typescript/_bundled_plugin/skills/attack-path-analysis/SKILL.md
sdk/typescript/_bundled_plugin/skills/deep-security-scan/SKILL.md
sdk/typescript/_bundled_plugin/skills/define-security-policy/SKILL.md
sdk/typescript/_bundled_plugin/skills/finding-discovery/SKILL.md
sdk/typescript/_bundled_plugin/skills/fix-finding/SKILL.md
sdk/typescript/_bundled_plugin/skills/security-diff-scan/SKILL.md
sdk/typescript/_bundled_plugin/skills/security-scan/SKILL.md
sdk/typescript/_bundled_plugin/skills/threat-model/SKILL.md
sdk/typescript/_bundled_plugin/skills/track-findings/SKILL.md
sdk/typescript/_bundled_plugin/skills/triage-finding/SKILL.md
sdk/typescript/_bundled_plugin/skills/validation/SKILL.md
sdk/typescript/_bundled_plugin/skills/vulnerability-writeup/SKILL.md
sdk/typescript/_bundled_plugin/skills/propose-security-hardening/SKILL.md

元信息

文件数
0
版本
bc124c3
Hash
3b10a60e
收录时间
2026-08-27 10:07

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-30 06:11
浙ICP备14020137号-1 $访客地图$