Skip to main content

/sec-audit-remediate

Generate targeted security fixes from detect-dev SARIF findings with regression tests.


Overview

Takes security findings from /detect-dev (SARIF format or security summary) and scaffold code to generate targeted fix patches, regression tests, and a remediation report. Supports CWE-mapped fix strategies with severity-based triage and confidence scoring.


Usage

/sec-audit-remediate
/sec-audit-remediate detect-dev-output [backend-scaffold | frontend-scaffold]
ArgumentRequiredDescription
detect-dev-outputNoPath to detect-dev SARIF or security summary
scaffold typeNobackend-scaffold or frontend-scaffold for code cross-reference

When run without arguments, searches for detect-dev outputs automatically.


What It Produces

Files at $JAAN_OUTPUTS_DIR/sec/remediate/{id}-{slug}/:

FileContent
{id}-{slug}.mdRemediation report with triage decisions
{id}-{slug}-fixes.patchFix patches per finding
{id}-{slug}-tests.tsRegression tests for each fix
{id}-{slug}-summary.mdExecutive summary with risk scores

What It Asks

QuestionWhenWhy
Remediation scopeAlwaysWhich findings to fix (all / critical / selected)
Fix aggressivenessMultiple strategies possibleMinimal patch vs comprehensive hardening
Test depthAlwaysRegression only vs full security test suite

CWE Coverage

Generates fixes for common vulnerability types:

CWECategoryStrategy
CWE-79XSSDOMPurify + CSP headers
CWE-89SQL InjectionParameterized queries
CWE-352CSRFToken validation middleware
CWE-798Hardcoded CredentialsEnvironment variable extraction
CWE-862Missing AuthZRBAC middleware

Workflow Chain

/detect-dev --> /sec-audit-remediate --> /devops-infra-scaffold (security in CI)

Example

Input:

/sec-audit-remediate path/to/detect-dev/security.md backend-scaffold

Output:

jaan-to/outputs/sec/remediate/01-auth-hardening/
├── 01-auth-hardening.md
├── 01-auth-hardening-fixes.patch
├── 01-auth-hardening-tests.ts
└── 01-auth-hardening-summary.md

Tips

  • Run /detect-dev first to generate SARIF findings
  • Start with critical/high severity findings for maximum impact
  • Review fix patches before applying to your codebase
  • Use /devops-infra-scaffold to add security scanning to CI


Technical Details

  • Logical Name: sec-audit-remediate
  • Command: /sec-audit-remediate
  • Role: sec
  • Output: $JAAN_OUTPUTS_DIR/sec/remediate/{id}-{slug}/