Skip to main content

patcher-overview

Stage 4 patch generation playbook. Minimal diffs for validated findings with mandatory patch_verify. Load at patcher-agent startup.

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年6月2日 17:35
检测到的 SKILL.md 语言
英语
星标
5,611
分支
1,061

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
patcher-overview
description
Stage 4 patch generation playbook. Minimal diffs for validated findings with mandatory patch_verify. Load at patcher-agent startup.
metadata
{"subdomain":"orchestration","when_to_use":"patcher stage 4 patch generation minimal diff validated finding patch_verify pipeline","upstream_ref":"Decepticon vulnresearch pipeline — stage 4 patcher role"}
# Patcher Skill You fix validated findings and prove the fix holds. Minimal diffs, one concern at a time, mandatory `patch_verify` before claiming done. ## Iteration loop ``` while not patched and attempts < 3: 1. kg_query(kind="vulnerability", min_severity="medium") → pick validated=True, patched!=True 2. Read the function around (file, line) 3. Design minimal fix (validate / escape / parameterize / safe API) 4. patch_propose(vuln_id, diff, commit_message) → patch_id 5. Apply diff via Edit or bash patch 6. (optional) bash: run repo tests, abort on failure 7. patch_verify(patch_id, poc_command, success_patterns, test_cmd=optional) 8. if status == "verified": done elif status == "tests_failed": revert, retry elif status == "regressed": revert, analyze, retry attempts += 1 ``` ## Diff style - **Unified diff.** Use `git diff --no-color` output or write one by hand. - **Minimal hunk.** One concern. No formatting. No renames. No "while I'm here" cleanups. No new files (unless adding one regression test). - **Safe-API preference.** | Bug class | Preferred fix | |-------------------------|------------------------------------------------------| | SQL injection | Parameterized query / ORM.filter(), NOT escaping | | Command injection | Arg-list subprocess, shell=False | | Path traversal | `os.path.realpath` + prefix check | | SSRF | Allowlist + resolve → check not private/loopback | | Deserialization | Switch to safe loader (`yaml.safe_load`, JSON, etc.) | | Broken auth | Move check to pre-hook, not inside handler | | Reflected XSS | Framework auto-escape, remove `Markup`/`safe` | - **Add a regression test** in the same diff when the repo has a test directory for the affected module. One test that exercises the fixed path is sufficient. ## Commit message format Conventional commits. Example: ``` fix(auth): use constant-time comparison in verify_hmac Prevents timing side-channel recovery of the HMAC. CWE-208. ``` ## Decisive-completion rule Only report "patched" after `patch_verify.status == "verified"`. A green test suite is NOT sufficient — the PoC must actually fail. If all 3 attempts fail, STOP on the finding, record a note via `kg_add_node` on the vuln (`patch_attempts=3, last_failure=...`) and return to the orchestrator. Do not spiral.
在 GitHub 查看