Skip to content
Back to skills

X Fix

ASecurity

Resolve the VSDB audit backlog sequentially, with one finding per validated local commit. Use only when the user explicitly invokes /x-fix.

  • 28 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agents

Security analysis

A100/100

Scanned October 2, 2026

npx -y skills add rust-util-collections/vsdb --skill x-fix --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of X Fix?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for X Fix
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rust-util-collections-x-fix/badge)](https://www.skillsdirectory.com/skills/rust-util-collections-x-fix)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: x-fix
description: Resolve the VSDB audit backlog sequentially, with one finding per validated local commit. Use only when the user explicitly invokes /x-fix.
disable-model-invocation: true
---

# Fix the VSDB Audit Backlog

Clear actionable `docs/audit.md` Open → self-review → local commits. Never push.
No tag. No autonomous major. User-invoked only. New commits only.

## Input

None. Non-empty `$ARGUMENTS` → reject; never guess a filter.

## Setup

Read `.claude/docs/workflow-policy.md`, `.claude/docs/commit-protocol.md`,
`.claude/docs/compatibility-policy.md`, `.claude/docs/pragmatic-engineering.md`,
`.claude/docs/review-core.md`, `.claude/docs/technical-patterns.md`,
`.claude/docs/false-positive-guide.md`. Preflight + ledger (freeze paths as work
proceeds; note whether a patch bump is owed). Empty Open and no owed bump →
“nothing to fix”. Empty Open but an owed bump → skip fixes; standalone continues
at step 4, and a composed run leaves the bump to the parent.

When composed by `x-overhaul`, inherit its scope, starting HEAD, and ledger;
run steps 1–3 only. The parent owns the final gate and version. Empty in-scope
Open skips fixes, not the parent's audit, validation, or owed bump.

## Protocol

### 1. Triage (CRITICAL → LOW)

Per entry before edit: code/callers/tests + guides (+ `.claude/docs/design-patterns.md`
if design); reproduce from current code; dedupe root causes; disproven → remove
the entry with refutation evidence; real and disproportionate to fix safely →
Won't Fix + reason. A break the user has not
accepted → leave Open; do not ship it. Missing evidence, failed validation, or
ownership overlap is a blocker, not a disposition: leave Open.

### 2. One finding → one commit (blocking)

1. Root-cause fix + focused regression.
2. Trace SWMR, COW, crash, cleanup, compatibility.
3. Drop that Open entry (code + tests + migration docs + registry = unit).
4. Per-unit validation (`.claude/docs/commit-protocol.md`).
5. Stage freeze + fix paths; inspect cached; commit before next.

Registry-only disposition = one unit. Same root cause may batch symptoms. Mutating
agents never parallel (read/validate may).

### 3. Self-review

Review `starting_HEAD..HEAD` + this invocation’s uncommitted paths with
`review-core.md` §3 evidence and the FP guide; registry per §5.
New confirmed → Open → same one-finding loop. Stop on no-progress or baseline overlap.

### 4. Final gate and version

`.claude/docs/commit-protocol.md` once. Required checks pass and no in-scope Open
remains → the owed bump. No tag. No autonomous major.
Blocked → retain validated local commits and report remaining Open; the owed bump
stays for the next run.

## Output

Dispositions, fixes, disproven entries removed / Won't Fix, validations, compatibility, hashes/subjects, version, baseline left alone.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…