Agent skill

Threat Patch

by pproenca in pproenca/dot-skills

Remediate security findings by producing minimal, surgical code patches.

MITAuto-check passedSecurity

Install Threat Patch

skills CLI
$ npx skills add pproenca/dot-skills --skill threat-patch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pproenca/dot-skills threat-patch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.experimental/threat-patch .claude/skills/threat-patch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-patch
GitHub stars
215
Token cost
~1.3k tokens
SKILL.md length
527 words
Files
9 (incl. scripts, references)
Skills in repo
41
Repo updated
First seen
Licence
MIT

At a glance

Remediate security findings by producing minimal, surgical code patches.

  • Works in 5 steps: Read workflow for the detailed patching… → Read fix patterns when designing fixes —… → Read output format for the documentation… → …
  • Patch security findings
  • SKILL.md covers When to Apply, Input Sources (priority order), Workflow Overview and How to Use, plus 4 more sections
  • Runs Shell scripts from its folder; calls git

What it does

Threat Patch is an agent skill from pproenca/dot-skills. Remediate security findings by producing minimal, surgical code patches. Triggers on 'patch security findings', 'fix vulnerabilities', 'remediate findings', 'threat patch', or when the user provides a findings.json (from threat-model), a Codex security findings CSV, a THREAT-MODEL.md, or individual vulnerability descriptions and wants them fixed. Also trigger when reviewing code flagged by a security scanner and the user wants actionable fixes rather than just reports.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `config.json`, `gotchas.md` and `hooks/hooks.json`).

It sits in Security, covering Threat modeling, Vulnerability scanning and CSV and tabular files. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.

When your agent uses it

  • Patch security findings
  • Fix vulnerabilities
  • Remediate findings
  • The user provides a findings.json (from threat-model)

Example prompts

  • “patch security findings”
  • “fix vulnerabilities”
  • “remediate findings”
  • “/threat-patch”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read workflow for the detailed patching methodology at each step
  2. Read fix patterns when designing fixes — common patterns by vulnerability class
  3. Read output format for the documentation template per patch
  4. If input is findings.json: read it directly — it's already structured
  5. If input is Codex CSV: run scripts/parse-findings.sh to extract structured output

What it can do on your machine

Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Patch loads about 1.3k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 527 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 527 words, ~1,347 tokens.

Download SKILL.mdSave it as .claude/skills/threat-patch/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
threat-patch
description
Remediate security findings by producing minimal, surgical code patches. Triggers on 'patch security findings', 'fix vulnerabilities', 'remediate findings', 'threat patch', or when the user provides a findings.json (from threat-model), a Codex security findings CSV, a THREAT-MODEL.md, or individual vulnerability descriptions and wants them fixed. Also trigger when reviewing code flagged by a security scanner and the user wants actionable fixes rather than just reports.

Threat Patch

Reads security findings and produces minimal, surgical code patches with structured documentation. Fixes are code-grounded — each patch targets specific files and functions identified in the finding. Output includes a summary, validation steps, and the code changes.

When to Apply

  • User provides a findings.json (from threat-model) and wants fixes
  • User provides a Codex security findings CSV and wants fixes
  • User has a THREAT-MODEL.md and wants to remediate identified risks
  • User describes a specific vulnerability and wants a patch
  • Reviewing security scanner output and needs actionable fixes
  • After a security audit, turning findings into code changes

Input Sources (priority order)

SourceWhat It ProvidesHow to Use
findings.json (from threat-model)Structured findings with data flow traces, systemic groupings, exploit chains, and severity ratingsRead directly — richest input, already triaged and grouped
Codex CSVTitle, description, severity, relevant_paths per findingRun scripts/parse-findings.sh <csv-path> to extract structured output
THREAT-MODEL.mdHuman-readable threat modelExtract findings from Criticality Calibration section
Inline descriptionUser describes a specific vulnerabilityParse from conversation context

When findings.json is available, it's the preferred input — it includes data flow traces (entry → chain → sink) that directly inform where to apply fixes, and systemic groupings that suggest centralized fixes over individual patches.

Workflow Overview

1. Ingest Findings   → Read findings.json / CSV / descriptions
2. Triage & Group    → Sort by severity, use systemic groupings if available
3. For each finding:
   a. Read Code      → Open relevant_paths, understand the pattern
   b. Confirm        → Verify issue is still present in HEAD
   c. Design Fix     → Determine minimal fix approach
   d. Implement      → Write the code changes
   e. Document       → Summary + Validation + Attack-path (if needed)
   f. Test           → Run relevant tests
4. Output            → Per-patch deliverable with summary and diff
5. Update State      → Mark patched findings in findings.json (if present)

How to Use

  1. Read workflow for the detailed patching methodology at each step
  2. Read fix patterns when designing fixes — common patterns by vulnerability class
  3. Read output format for the documentation template per patch
  4. If input is findings.json: read it directly — it's already structured
  5. If input is Codex CSV: run scripts/parse-findings.sh <csv-path> to extract structured output
Show full SKILL.md (265 more words)Show less

Key Principles

  • Minimal diff: Fix the vulnerability, don't refactor surrounding code. The smallest correct patch is the best patch
  • Centralize over duplicate: When multiple code paths share the same vulnerability pattern, extract a shared helper rather than patching each site independently
  • Explicit error paths: Add specific error types for rejected inputs with clear operator feedback, not silent failures or generic errors
  • Confirm before fixing: Always verify the finding is still present in HEAD — code may have moved or been refactored since the finding was detected
  • User approval before edits: Present the fix design (files to change, approach) and wait for approval before modifying source code. Hooks gate Edit/Write tool calls for additional safety
  • Document even failures: When a fix can't be tested due to environment limitations, document the test command and the limitation

Guardrails

This skill modifies source code. Safety measures:

  • PreToolUse hooks on Edit and Write tools prompt for confirmation before each file change
  • Confirmation gate in the workflow between fix design and implementation
  • Revert path: Without commits (default), use git checkout -- <files> to undo. With commits, use git revert

Output Modes

Code patch — when a fix is implemented:

  • Summary of what was confirmed and what the fix does
  • Testing section with build/test commands
  • The actual code changes

Analysis only — when the fix needs user decision or architectural changes:

  • Summary of what was confirmed
  • Validation checklist
  • Attack-path analysis (path, likelihood, impact, assumptions, controls, blindspots)

References

FileWhen to Read
references/workflow.mdBefore starting — detailed approach for each patching phase
references/fix-patterns.mdWhen designing fixes — patterns by vulnerability class
references/output-format.mdWhen documenting — templates for both output modes

© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in skills/.experimental/threat-patch of pproenca/dot-skills.

  • SKILL.md
  • config.json
  • gotchas.md
  • hooks/hooks.json
  • metadata.json
  • references/fix-patterns.md
  • references/output-format.md
  • references/workflow.md
  • scripts/parse-findings.sh

Open the folder on GitHubat commit cf93c57

Compare with similar skills

Threat Patch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Patch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Patch this skillpproenca/dot-skills215—~1.3kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Senior SecurityLeoYeAI/openclaw-master-skills2.2k—~3.8kAutomated safety check: PassMIT
Security Ownership Mapdiegosouzapw/awesome-omni-skills159—~4.6kAutomated safety check: PassApache-2.0
Defender Easmvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Senior Security

    LeoYeAI/openclaw-master-skills

    Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Ownership Map

    diegosouzapw/awesome-omni-skills

    Security Ownership Map workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.6k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Defender Easm

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Vulnerability Scanner

    Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI

    Advanced vulnerability analysis principles. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI.

    507 GitHub stars~494 tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from pproenca/dot-skills

All 41 skills in this repo
  • Audio Voice Recovery

    pproenca/dot-skills

    Audio forensics and voice recovery guidelines for CSI-level audio analysis.

    215 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Codemod React Pipeline

    pproenca/dot-skills

    Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.

    215 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Dev Rfc

    pproenca/dot-skills

    Create well-structured RFCs and technical proposals for software projects.

    215 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Dx Harness

    pproenca/dot-skills

    Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.

    215 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Language Spec Author

    pproenca/dot-skills

    Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…

    215 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Python Pep Author

    pproenca/dot-skills

    Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…

    215 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Threat Patch

What does Threat Patch do?

Remediate security findings by producing minimal, surgical code patches. Threat Patch is an agent skill from pproenca/dot-skills. Remediate security findings by producing minimal, surgical code patches.

When should I use Threat Patch?

Threat Patch fits situations like: patch security findings; fix vulnerabilities; remediate findings; the user provides a findings.json (from threat-model).

How do I install Threat Patch in Claude Code?

Run `npx skills add pproenca/dot-skills --skill threat-patch -a claude-code`. Or copy the skill folder (skills/.experimental/threat-patch in pproenca/dot-skills) into .claude/skills/threat-patch in your project. Claude Code loads it when a task matches its description.

How do I install Threat Patch in Codex?

Run `npx skills add pproenca/dot-skills --skill threat-patch -a codex`. Or copy the skill folder (skills/.experimental/threat-patch in pproenca/dot-skills) into .agents/skills/threat-patch in your project. Codex loads it when a task matches its description.

Can I use Threat Patch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill threat-patch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-patch, .gemini/skills/threat-patch, .github/skills/threat-patch and .opencode/skills/threat-patch in your project.

What does Threat Patch need to run?

Going by SKILL.md and its folder, Threat Patch needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell.

Does Threat Patch access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Threat Patch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Threat Patch use?

Threat Patch is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Patch use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.6k tokens, read only when the agent opens those files.

What are the alternatives to Threat Patch?

Skills that share tags, products or a category with Threat Patch: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Senior Security (LeoYeAI/openclaw-master-skills, 2.2k stars) and Security Ownership Map (diegosouzapw/awesome-omni-skills, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Patch?

pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 215 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on August 15, 2026.

Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.