Official agent skill

Fix Security Issue

by NVIDIA in NVIDIA/OpenShell

Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.

OfficialApache-2.0Auto-check passedDevelopment

Install Fix Security Issue

skills CLI
$ npx skills add NVIDIA/OpenShell --skill fix-security-issue -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/OpenShell fix-security-issue --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fix-security-issue .claude/skills/fix-security-issue && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-security-issue
GitHub stars
15k
Token cost
~596 tokens
SKILL.md length
313 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.

  • Works in 5 steps: Fetch the issue and its comments with gh… → Verify the review against current code.… → Create a fix branch or worktree… → …
  • Tasks that involve Pull requests
  • Calls gh

What it does

Fix Security Issue is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. The repository describes itself as: OpenShell is the safe, private runtime for autonomous AI agents. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Pull requests

Example prompts

  • “/fix-security-issue”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Fetch the issue and its comments with gh issue view --json number,title,body,state,labels,comments. Follow Label Discovery in…
  2. Verify the review against current code. Adapt the plan when code has changed, and record material deviations. Check for an existing owner…
  3. Create a fix branch or worktree following Branch Names in CONTRIBUTING.md, preserving unrelated changes and disclosure boundaries…
  4. Follow the verification guidance in CONTRIBUTING.md. Run format, lint, compile or type checks, and regression tests for the affected…
  5. Follow create-github-pr and use Closes # for the reviewed issue. Every PR from this issue-backed remediation workflow must close its own…

What it can do on your machine

Read from SKILL.md and the folder at commit 834b79a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Security Issue loads about 596 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 313 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~596

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/OpenShell at commit 834b79a, republished under its Apache-2.0 licence (© NVIDIA). 313 words, ~596 tokens.

Download SKILL.mdSave it as .claude/skills/fix-security-issue/SKILL.md (or your agent's skills folder).
name
fix-security-issue
description
Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.
metadata.internal
true

Fix Security Issue

Use this skill after an authorized review-security-issue review identifies an actionable concern. Follow SECURITY.md; do not disclose vulnerability details in a public issue. A direct user request to fix a specific reviewed issue authorizes implementation. For unattended work, inspect current state:* label descriptions, maintainer assignments, and comments to verify that remediation is authorized. Do not infer approval from a state that only records technical validation.

  1. Fetch the issue and its comments with gh issue view <id> --json number,title,body,state,labels,comments. Follow Label Discovery in CONTRIBUTING.md and confirm this is a security issue; resolve unclear meanings before interpreting authorization. Find the review marked > **🔒 security-review-agent** and its remediation plan. If the review is missing or found the issue not actionable, stop and report that result.
  2. Verify the review against current code. Adapt the plan when code has changed, and record material deviations. Check for an existing owner, branch, or PR.
  3. Create a fix branch or worktree following Branch Names in CONTRIBUTING.md, preserving unrelated changes and disclosure boundaries. Implement the smallest safe fix and add regression tests for the security boundary. Avoid logging secrets or adding public exploit detail.
  4. Follow the verification guidance in CONTRIBUTING.md. Run format, lint, compile or type checks, and regression tests for the affected security boundary and dependent components, plus the relevant E2E lane for sandbox or policy changes. Broaden verification when the fix spans components or a concrete risk remains; do not require unaffected Rust or SDK suites solely to create a signed-off commit or PR.
  5. Follow create-github-pr and use Closes #<id> for the reviewed issue. Every PR from this issue-backed remediation workflow must close its own issue; split multi-PR remediations into separate issues in the authorized security workflow. Keep the PR description appropriately scoped to its disclosure venue.

Begin any fix comments with > **🔧 security-fix-agent**. Do not change human disposition or introduce agent:* workflow labels.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/fix-security-issue of NVIDIA/OpenShell.

Open the folder on GitHubat commit 834b79a

Compare with similar skills

Fix Security Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Security Issue compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Security Issue this skillNVIDIA/OpenShell15k—~596Automated safety check: PassApache-2.0
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from NVIDIA/OpenShell

All 23 skills in this repo
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Create GitHub Issue

    NVIDIA/OpenShell

    Official

    Create GitHub issues using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create GitHub PR

    NVIDIA/OpenShell

    Official

    Create GitHub pull requests using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Inference

    NVIDIA/OpenShell

    Official

    Debug inference clients that use an attached provider and its native endpoint, including hosted APIs and host-local Ollama, vLLM, SGLang, TRT-LLM, LM Studio, or NIM.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    15k GitHub stars~19k tokensUpdated today
    Auto-check: notes
  • Gator Gate

    NVIDIA/OpenShell

    Official

    Validate and monitor OpenShell GitHub issues and PRs using the gator: state machine.

    15k GitHub stars~19k tokensUpdated today
    Auto-check passed

Categories

Questions about Fix Security Issue

What does Fix Security Issue do?

Implement an authorized fix for a reviewed security issue and open a PR that closes its issue. Fix Security Issue is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Implement an authorized fix for a reviewed security issue and open a PR that closes its issue.

When should I use Fix Security Issue?

Fix Security Issue fits situations like: tasks that involve Pull requests.

How do I install Fix Security Issue in Claude Code?

Run `npx skills add NVIDIA/OpenShell --skill fix-security-issue -a claude-code`. Or copy the skill folder (.agents/skills/fix-security-issue in NVIDIA/OpenShell) into .claude/skills/fix-security-issue in your project. Claude Code loads it when a task matches its description.

How do I install Fix Security Issue in Codex?

Run `npx skills add NVIDIA/OpenShell --skill fix-security-issue -a codex`. Or copy the skill folder (.agents/skills/fix-security-issue in NVIDIA/OpenShell) into .agents/skills/fix-security-issue in your project. Codex loads it when a task matches its description.

Can I use Fix Security Issue in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/OpenShell --skill fix-security-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-issue, .gemini/skills/fix-security-issue, .github/skills/fix-security-issue and .opencode/skills/fix-security-issue in your project.

What does Fix Security Issue need to run?

Going by SKILL.md and its folder, Fix Security Issue needs the command-line tools its instructions call (gh).

Does Fix Security Issue access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fix Security Issue safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fix Security Issue use?

Fix Security Issue is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Security Issue use?

About 596 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Security Issue?

Skills that share tags, products or a category with Fix Security Issue: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Security Issue?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/OpenShell, which has 15,188 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/OpenShell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.