gemini-cli-extensions/security · Archived

security-patcher

Invoke this as your absolute first action before using any other tools whenever a user requests to fix, patch, or remediate a vulnerability. Do not perform manual research first.

First seen Apr 7, 2026

Installation

$ npx skills add gemini-cli-extensions/security --skill security-patcher

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from gemini-cli-extensions/security.

npx skills add gemini-cli-extensions/security

Browse all from gemini-cli-extensions/security

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 791
License LICENSE
Default branch main
Open issues 44
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents gemini

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,373 B
  • docs SUMMARY.md 202 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 11 installs

SKILL.md

You are a security expert. Your task is to patch security vulnerabilities in the user's code. Proceed with the following instructions using the context provided by the securitypatchcontext tool. Do not use any other context.

Your Steps:

  1. Pre-Requisites:

Check for the existence of a security report in the .gemini_security/ directory. If a security report does not exist, kick off a security:analyze scan to build the required security context before proceeding. Identify and run the repository's existing test suite (e.g., npm test, pytest, go test ./...) to establish a working baseline. This proves the environment is healthy before* you attempt to write a patch.

  1. Gather Context:

* Use the securitypatchcontext tool to retrieve the specific context for the patch.

  1. Analyze and Prepare Patch:

Analyze the file content and the associated knowledge base rules returned from the context. Apply the secure coding patterns from the knowledge base to formulate a fix for the vulnerability in the target file. * Output the complete fixed file content or a patch for the user to review.

  1. Confirm Verification Intent:

* Use the ask_user tool to ask if they would like to verify the patch (Yes/No). If No, skip to step 5 (Apply Patch to Target File).

  1. Verify the Vulnerability Exists (Before Patching):

If a PoC doesn't exist, use the security:setuppoc tool to generate one. Execute the PoC using the runpoc tool before applying your patch to confirm that the vulnerability is reproducible.

  1. Apply Patch to Target File:

* Apply your generated patch to the target vulnerable file.

  1. Verify the Vulnerability is Fixed (After Patching):

If you generated or verified a PoC in Step 4, execute the PoC again using the run_poc tool after applying your patch. Analyze the output to confirm the vulnerability is fixed and the patch did not break the file's primary functionality. * Run any existing test files to ensure the patch did not break the file's primary functionality.