smithery/robotti-io

secure-fix-validation

Standard validation checklist to prove a security fix works and doesn’t regress behavior.

Installation

$ npx skills add smithery/robotti-io --skill secure-fix-validation

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/robotti-io.

npx skills add smithery/robotti-io

Browse all from smithery/robotti-io

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,665 B
  • docs SUMMARY.md 120 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Secure Fix Validation

When to use

Use this skill after implementing a security fix, or when reviewing a PR.

Inputs to collect (if available)

  • Vulnerability description and expected secure behavior
  • Repro steps (request, payload, or test)
  • Affected components and entry points
  • Deployment/rollout constraints (feature flags, backwards compatibility)

Step-by-step process

  1. Reproduce the issue pre-fix

- Minimal failing test or request example

  1. Verify the fix

- Confirm the repro now fails safely

  1. Regression coverage

- Add unit/integration tests for: - expected valid inputs - malicious/edge inputs - authorization bypass attempts (if relevant)

  1. Non-functional checks

- Error handling (no stack traces/secret leakage) - Logging redaction (no PII/secrets) - Performance impact in hot paths

  1. Rollout safety

- Feature flags where appropriate - Backwards compatibility notes - Monitoring/alerts to detect new failure modes

Output

  • Commands run
  • Tests added/updated
  • Verification evidence (logs/screenshots/snippets)
  • Rollout notes

Output format

  • Repro (pre-fix): how it failed
  • Verification (post-fix): what now happens
  • Tests: added/updated + what they cover
  • Evidence: logs/screenshots/snippets (redacted)
  • Rollout notes: monitoring, flags, compatibility

Examples

  • “Fix: block IDOR on /users/:id” → add negative test for cross-user access; verify 403 and tenant scoping on DB query.