agentsclimarketplace

Run3 patch generation

Skill cxcscmu/SkillLearnBench/skills/b3-teacher-feedback-gemini-3.1-flash-lite-preview/fix-security-bug/run3_patch-generation

Generating and saving git-compatible patch files for Apache Druid source code.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run3_patch-generation

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

0.9 KB, 188 tokens by cl100k_base, as published. Nobody here has run it

To address the vulnerability, identify the JavaScriptConfig class responsible for deserializing the malicious payload. Use grep to locate the handling of the empty string key "".

Create a patch file at /root/patches/fix-js-config.patch that removes the setter method or the logic inside JavaScriptConfig (or its factory/builder) that maps the empty string to the enabled configuration.

Example approach:

  1. Locate src/main/java/org/apache/druid/js/JavaScriptConfig.java.
  2. Inspect the JSON deserialization logic. If there is a method like set or a @JsonCreator that accepts "", modify the code to ignore or explicitly throw an exception when such a key is encountered.
  3. Generate the patch using:
    cd /root/druid
    git diff > /root/patches/fix-js-config.patch
    

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.