Loop security patch retest
Configure Codex, Claude, and Tabnine to understand your project, follow its workflow, and respect its safety rules.
npx -y skills add jsuvic/agent-profile --skill loop-security-patch-retestAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use to run a bounded security-review, patch, and retest loop that stops on green, on no diff, or on a repeated identical finding.
SKILL.md
1.7 KB, as published. Nobody here has run it
Loop: Security Review, Patch, Retest
Iterate on security-sensitive findings for a change until they are resolved, bounded by a hard iteration cap. Each iteration reviews for security risk, patches, and retests.
Loop Steps
- Review the change for security-sensitive behavior and injection, secret-handling, and permission risks.
- Patch the highest-severity finding with a focused, minimal change.
- Rerun the relevant tests and checks and confirm the risk is resolved without regressions.
Max Iterations
The loop runs at most 3 iterations. When it reaches 3 iterations without meeting a stop condition, it stops unconditionally and reports the unfinished state and the outstanding work; it never raises the bound to keep going.
Stop Conditions
Stop the loop as soon as any of these holds:
- The relevant tests and checks are green.
- An iteration produces no diff.
- The same failure repeats identically across two consecutive iterations.
Approval Gate
- Get explicit human approval before any write, commit, or destructive step in each iteration.
- The loop never self-approves, never continues past the iteration bound, and never runs destructive commands on its own authority.
- Pause and surface the state whenever approval is missing.
Safety
- Do not upload source code.
- Do not read or print secrets.
- APC does not run this loop; a human or agent follows these instructions and remains in control.