- 27 official team skills (Sentry, Trail of Bits, Expo, Hugging Face, etc.) - 34 community skills including context engineering suite - All skills validated and compliant with V4 quality bar - Complete source attribution maintained Skills added: - Official: commit, create-pr, find-bugs, iterate-pr, culture-index, fix-review, sharp-edges, expo-deployment, upgrading-expo, hugging-face-cli, hugging-face-jobs, vercel-deploy-claimable, design-md, using-neon, n8n-*, swiftui-expert-skill, fal-*, deep-research, imagen, readme, screenshots - Community: frontend-slides, linear-claude-skill, skill-rails-upgrade, context-*, multi-agent-patterns, tool-design, evaluation, memory-systems, terraform-skill, and more
54 lines
1.8 KiB
Markdown
54 lines
1.8 KiB
Markdown
---
|
|
name: fix-review
|
|
description: "Verify fix commits address audit findings without new bugs"
|
|
source: "https://github.com/trailofbits/skills/tree/main/plugins/fix-review"
|
|
risk: safe
|
|
---
|
|
|
|
# Fix Review
|
|
|
|
## Overview
|
|
|
|
Verify that fix commits properly address audit findings without introducing new bugs or security vulnerabilities.
|
|
|
|
## When to Use This Skill
|
|
|
|
Use this skill when you need to verify fix commits address audit findings without new bugs.
|
|
|
|
Use this skill when:
|
|
- Reviewing commits that address security audit findings
|
|
- Verifying that fixes don't introduce new vulnerabilities
|
|
- Ensuring code changes properly resolve identified issues
|
|
- Validating that remediation efforts are complete and correct
|
|
|
|
## Instructions
|
|
|
|
This skill helps verify that fix commits properly address audit findings:
|
|
|
|
1. **Review Fix Commits**: Analyze commits that claim to fix audit findings
|
|
2. **Verify Resolution**: Ensure the original issue is properly addressed
|
|
3. **Check for Regressions**: Verify no new bugs or vulnerabilities are introduced
|
|
4. **Validate Completeness**: Ensure all aspects of the finding are resolved
|
|
|
|
## Review Process
|
|
|
|
When reviewing fix commits:
|
|
|
|
1. Compare the fix against the original audit finding
|
|
2. Verify the fix addresses the root cause, not just symptoms
|
|
3. Check for potential side effects or new issues
|
|
4. Validate that tests cover the fixed scenario
|
|
5. Ensure no similar vulnerabilities exist elsewhere
|
|
|
|
## Best Practices
|
|
|
|
- Review fixes in context of the full codebase
|
|
- Verify test coverage for the fixed issue
|
|
- Check for similar patterns that might need fixing
|
|
- Ensure fixes follow security best practices
|
|
- Document the resolution approach
|
|
|
|
## Resources
|
|
|
|
For more information, see the [source repository](https://github.com/trailofbits/skills/tree/main/plugins/fix-review).
|