Security Fixer — Security agent for Claude Code
Implement the minimal fix for a confirmed security finding with a working PoC.
How to install Security Fixer
Installs to ~/.claude/agents/wrxck-auto-audit-security-fixer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/wrxck/auto-audit/HEAD/agents/security-fixer.md -o ~/.claude/agents/wrxck-auto-audit-security-fixer.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Fixer does
name: security-fixer description: "Implement the minimal fix for a confirmed security finding with a working PoC. Creates a branch, edits source files, runs project tests if they exist, and commits. Does NOT open the PR. Invoke when a finding is in `poc_written` state." tools: "Bash Read Edit Write Grep Glob" model: "claude-sonnet-4-6"
You are a senior engineer. Your job is to apply the **smallest possible fix** that removes the vulnerability's exploit path, without refactoring surround
Alternatives in Security
- Security Hardening — Implement comprehensive security hardening with defense-in-depth strategy through coordinated multi 31.9k ★
- Genblaze Maintainer — The Genblaze Maintainer — autonomous guardian of the Genblaze repo 560 ★
- Security Verifier — You write and execute PoC tests to PROVE bugs exist 215 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
POC Builder
Build a minimal proof of concept for a confirmed security finding. Writes a failing test, a small script, or a
Vuln Patcher
Writes minimal, verified fix patches for confirmed vulnerabilities as diff files under reports/, without modif
Issue Manager
Manages the GitHub issue lifecycle for claude-code-vault. Creates well-structured issues from review/audit fin
After Confirming A Vulnerability
findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat
POC Engineer
Given a confirmed finding + its context worksheet, produces the smallest self-contained crate that reproduces
Vuln Discloser
Re-verifies confirmed findings against the latest upstream release and drafts maintainer-ready security adviso
Related Skills
POC
Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain,
Report Draft
Draft a HackerOne bug bounty report from a validated finding. Only invoke this after a full end-to-end PoC exi
Review Commit PR Discipline
Review the current branch's commits and working tree for commit and pull-request discipline, then produce well