# Loop Security Patch Retest

> Use to run a bounded security-review, patch, and retest loop that stops on green, on no diff, or on a repeated identical finding.

- Skill: `jsuvic/loop-security-patch-retest` (Agent Skill)
- Install (CLI): `npx skillmds@latest add jsuvic/loop-security-patch-retest`
- Raw SKILL.md: https://api.skillmd.com/api/skills/jsuvic/loop-security-patch-retest/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: jsuvic (https://skillmd.com/u/jsuvic)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/jsuvic/loop-security-patch-retest

---


<!-- Generated by Agent Profile Compiler. Do not edit by hand. -->

# Loop: Security Review, Patch, Retest

Iterate on security-sensitive findings for a change until they are resolved, bounded by a hard iteration cap. Each iteration reviews for security risk, patches, and retests.

## Loop Steps

1. Review the change for security-sensitive behavior and injection, secret-handling, and permission risks.
2. Patch the highest-severity finding with a focused, minimal change.
3. Rerun the relevant tests and checks and confirm the risk is resolved without regressions.

## Max Iterations

The loop runs at most 3 iterations. When it reaches 3 iterations without meeting a stop condition, it stops unconditionally and reports the unfinished state and the outstanding work; it never raises the bound to keep going.

## Stop Conditions

Stop the loop as soon as any of these holds:

- The relevant tests and checks are green.
- An iteration produces no diff.
- The same failure repeats identically across two consecutive iterations.

## Approval Gate

- Get explicit human approval before any write, commit, or destructive step in each iteration.
- The loop never self-approves, never continues past the iteration bound, and never runs destructive commands on its own authority.
- Pause and surface the state whenever approval is missing.

## Safety

- Do not upload source code.
- Do not read or print secrets.
- APC does not run this loop; a human or agent follows these instructions and remains in control.

