Fix review
Checks that a fix actually closes the reported issue and did not just move it.
Installation
$ npx skills add trailofbits/skillsThe CLI's unit is the repository, so this installs everything in trailofbits/skills, not fix-review alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.
Summary
Checks that a fix actually closes the reported issue and did not just move it.
- Reach for it when verifying a security patch before you tell the reporter it is resolved.
- Spans Review and Secure, so it is usually worth loading for the whole piece of work rather than at one moment in it.
- Stack-agnostic — nothing in it assumes a particular language or framework.
- Published by Trail of Bits. Well regarded, but not the vendor of the thing it covers.
- Installing pulls the whole trailofbits/skills repository: this catalogue lists 12 other entries from it, and the repo may hold more.
Where it sits in delivery
ReviewReading a diff critically, and the far harder skill of acting on what a reviewer said.Everything in Review →
SecureThreat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.Everything in Secure →
The agent itself
The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.
Related
More in Review
- Differential security reviewSecurity-focused review of a PR, commit or diff — risk-first, evidence-backed, with stated coverage limits.
trailofbits/skills - Address PR commentsWorks through review comments on a pull request and responds to or resolves each one.
openai/skills - Security threat modelProduces a threat model for a feature or system — assets, entry points, trust boundaries, mitigations.
openai/skills - Requesting code reviewDispatches a reviewer with fresh context, so the review is not done by the model that just wrote the code.
obra/superpowers - Agentic actions auditorAudits CI workflows that invoke AI agents — where prompt injection becomes a repository write.
trailofbits/skills - Security best practicesOpenAI's secure-coding guidance for agent-written code.Skill
openai/skills