> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentgg.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Suggested fixes

> Each confirmed finding comes with a suggested fix, shown as a diff in its report.

For each confirmed finding that is not a duplicate, agentgg reads the vulnerable code and the proof behind the verdict, then writes a code change that removes the cause. Your source code stays as it is until you apply the fix.

Suggested fixes are on by default. To turn them off, pass `--no-fix`.

## Read a fix

The fix appears in the finding file under `### Suggested fix`. It starts with a short explanation, followed by the location and a diff for each file it changes.

````markdown theme={null}
### Suggested fix
The login handler puts the raw username and password into the SQL text. Use a placeholder query and pass the values as parameters.

**Location:** `src/server.ts`, line 68

```diff
--- a/src/server.ts
+++ b/src/server.ts
@@ -68,1 +68,2 @@ line 68
-      `SELECT * FROM users WHERE username='${username}' AND password='${password}'`,
+      "SELECT * FROM users WHERE username=? AND password=?",
+      [username, password],
```
````

<Info>
  agentgg checks the fix against your current code, but it does not run or test it. Review a suggested fix as you would any code change, and run your tests after you apply it.
</Info>

## Write fixes for a finished scan

Run `agentgg fix` on the output directory:

```bash theme={null}
agentgg fix ./out
```

Use it after a scan with `--no-fix`, or after `agentgg revalidate` or `agentgg live-validate` confirms more findings. It skips findings that already have a fix. To write all fixes again, pass `--force`.

For all flags, see [Scan flags](/cli/reference/scan-flags).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.