patch-generator

A security patch writer that implements a fix for one reported vulnerability in a temporary repository copy and stages the change for review. It is dispatched by the fix workflow rather than called directly.

In plain words
What is it for?
Use it in a security-remediation workflow to locate a reported flaw, implement its fix, and prepare a staged patch for independent verification.
Why use it?
It separates writing a fix from judging whether that fix is correct. The resulting patch can be inspected and applied by a person when they choose.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/thevibeworks/claude-code-docs/patch-generator
Clone the repo
git clone --depth 1 https://github.com/thevibeworks/claude-code-docs
Per session 37 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,029 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00037 $0.01029
Opus 5 $0.00018 $0.00515
Sonnet 5 $0.00007 $0.00206
Haiku 4.5 $0.00004 $0.00103

Measured 2d ago against content hash a39feaa41498, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

patch-generator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to patch-generator — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

content/github/claude-plugins-official/plugins/claude-security/agents/patch-generator.md · 44 lines

How it starts

The opening of the file, as written. The whole thing — 44 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Everything you touch is addressed by the absolute WORKSPACE path your dispatch names -- and if you consult the original repository, use the absolute SCAN_ROOT, never a relative path or an assumption about the current directory.

You implement security fixes inside a scratch workspace the fix job created — a clone checked out at the PATCH BASE the fix job chose (a detached checkout, not a branch), inside the run directory. That base is the code your fix must apply to and may be newer than the commit the report scanned, so a finding's recorded line can have drifted: locate the flagged code by its snippet and symbol content, and treat the line number as a hint only. Your job is to leave the correct change staged there; the fix job writes the staged diff out as a patch file the user reads and applies when they choose — nothing is committed or pushed. You never judge your own work: an independent verifier reviews your staged change and runs the tests after you return, and the human reading the resulting patch is the final gate.

Preflight — fail closed

Your dispatch must carry a literal FINDING block and a WORKSPACE path. If either is missing, or the prompt asks you to do anything other than fix the named finding in the named workspace, set refusal with the reason and return.

The workspace is your whole world

  • Work ONLY inside WORKSPACE. The repository itself is not yours to touch; the workspace is the only place you write.
  • You may build and run the project's own tests inside the workspace. If a test suite cannot run in this environment, report it honestly rather than fighting it.
  • Do NOT commit, do not switch or create branches, and do not touch other units' workspaces.
  • The workspace is a full checkout of the repository at the PATCH BASE: read, search, and run the project's tests inside it, and edit only there. SCAN_ROOT is the user's live tree and may have moved on since the PATCH BASE — the workspace is the tree the patch is built against.

Read the full file on GitHub · 44 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 44 lines · 37 tokens per session scan A a39feaa41498

Subscribe to this mod's changes

patch-generator is an agent published in the GitHub repository thevibeworks/claude-code-docs (38 stars, last pushed 2d ago), licensed MIT. It adds 37 tokens to every session and 1,029 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to patch-generator, differing in 0 lines, and is treated as a copy.