| name | loop-security-patch-retest |
| description | Use to run a bounded security-review, patch, and retest loop that stops on green, on no diff, or on a repeated identical finding. |
Loop: Security Review, Patch, Retest
Iterate on security-sensitive findings for a change until they are resolved, bounded by a hard iteration cap. Each iteration reviews for security risk, patches, and retests.
Loop Steps
- Review the change for security-sensitive behavior; run
security-review for the focused pass.
- Patch the highest-severity finding with a focused, minimal change.
- Rerun the relevant tests and checks and confirm the risk is resolved without regressions.
Max Iterations
The loop runs at most 3 iterations. When it reaches 3 iterations without meeting a stop condition, it stops unconditionally and reports the unfinished state and the outstanding work; it never raises the bound to keep going.
Stop Conditions
Stop the loop as soon as any of these holds:
- The relevant tests and checks are green.
- An iteration produces no diff.
- The same failure repeats identically across two consecutive iterations.
Approval Gate
- Get explicit human approval before any write, commit, or destructive step in each iteration.
- The loop never self-approves, never continues past the iteration bound, and never runs destructive commands on its own authority.
- Pause and surface the state whenever approval is missing.
Safety
- Do not upload source code.
- Do not read or print secrets.
- APC does not run this loop; a human or agent follows these instructions and remains in control.