Skip to main content
For each confirmed finding that is not a duplicate, agentgg reads the vulnerable code and the proof behind the verdict, then writes a code change that removes the cause. Your source code stays as it is until you apply the fix. Suggested fixes are on by default. To turn them off, pass --no-fix.

Read a fix

The fix appears in the finding file under ### Suggested fix. It starts with a short explanation, followed by the location and a diff for each file it changes.
agentgg checks the fix against your current code, but it does not run or test it. Review a suggested fix as you would any code change, and run your tests after you apply it.

Write fixes for a finished scan

Run agentgg fix on the output directory:
Use it after a scan with --no-fix, or after agentgg revalidate or agentgg live-validate confirms more findings. It skips findings that already have a fix. To write all fixes again, pass --force. For all flags, see Scan flags.