Skip to main content

security-vulnerability-repair

Use this skill when the user wants software-fix data focused on security bugs such as injections, missing checks, unsafe parsing, broken access control, cryptographic mistakes, or information leaks. Trigger it for requests like 'make security repair tasks', 'generate vulnerability-fixing data', 'give me code issues with CWE-style fixes', or 'create patching tasks for insecure code'. Do not use it for ordinary non-security defects or for security exploitation tasks where the objective is to attack rather than repair.

跳到安装

来源信息

仓库
Dingxingdi/paper_fast_search_backup
最近来源活动
2026年4月8日 15:14
检测到的 SKILL.md 语言
英语
星标
0
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
4 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
security-vulnerability-repair
description
Use this skill when the user wants software-fix data focused on security bugs such as injections, missing checks, unsafe parsing, broken access control, cryptographic mistakes, or information leaks. Trigger it for requests like 'make security repair tasks', 'generate vulnerability-fixing data', 'give me code issues with CWE-style fixes', or 'create patching tasks for insecure code'. Do not use it for ordinary non-security defects or for security exploitation tasks where the objective is to attack rather than repair.
# Skill: security-vulnerability-repair ## 1. Capability Definition & Real Case * **Professional Definition**: The ability to identify and repair a security-relevant flaw in a codebase using vulnerability descriptions, failing security tests, and repository context, while preserving intended functionality and avoiding superficial non-security edits. * **Dimension Hierarchy**: Repository Maintenance and Repair->Issue-Driven Repair->security-vulnerability-repair ### Real Case **[Case 1]** * **Initial Environment**: A web application repository includes a failing test showing that crafted login input can bypass authentication by altering the generated query. The repository contains request handlers, query helpers, and authentication tests. * **Real Question**: Repair the login flow so malicious input cannot change the meaning of the database query. * **Real Trajectory**: Trace the login request from handler to query construction, confirm unsafe string interpolation, replace it with parameterized query handling, and run the targeted authentication security tests plus standard login regressions. * **Real Answer**: The login path now binds user input safely and rejects malicious query-shaping input while preserving valid authentication behavior. * **Why this demonstrates the capability**: This is a security-repair task because the failure is defined by exploitability rather than ordinary correctness alone. The agent must understand the vulnerability mechanism, patch the security boundary, and verify both exploit closure and preserved functionality. --- **[Case 2]** * **Initial Environment**: A Java service includes a vulnerability report explaining that a token-validation step omits an integrity check before accepting a session token. Regression tests include one newly failing security case and multiple passing session-management tests. * **Real Question**: Add the missing cryptographic validation step before accepting session tokens. * **Real Trajectory**: Inspect the token verification path, compare expected validation sequence with neighboring helpers, insert the integrity check before claims are trusted, and rerun the security test together with session lifecycle tests. * **Real Answer**: Session tokens are only accepted after the full validation sequence completes, including the previously omitted integrity verification step. * **Why this demonstrates the capability**: The task specifically evaluates security vulnerability repair because the patch must restore a protection guarantee, not just satisfy an arbitrary assertion. The correct trajectory requires security-aware reasoning about validation order and trust boundaries. ## Pipeline Execution Instructions To synthesize data for this capability, you must strictly follow a 3-phase pipeline. **Do not hallucinate steps.** Read the corresponding reference file for each phase sequentially: 1. **Phase 1: Environment Exploration** Read the exploration guidelines to discover raw knowledge seeds: `references/EXPLORATION.md` 2. **Phase 2: Trajectory Selection** Once Phase 1 is complete, read the selection criteria to evaluate the trajectory: `references/SELECTION.md` 3. **Phase 3: Data Synthesis** Once a trajectory passes Phase 2, read the synthesis instructions to generate the final data: `references/SYNTHESIS.md`
在 GitHub 查看