Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Vulnerability fixer

vulnerability-fixer.workflow.yaml
# Example: an agentic workflow that investigates and fixes a CVE in a repository.
# Profiles exercised: core, governance, audit, mcp.
apiVersion: awp.agenticworkflowprotocol.org/v1alpha1
kind: Workflow
metadata:
name: vulnerability-fixer
version: 0.1.0
description: Investigate a CVE in a repository, prepare a fix and open a pull request.
owner:
team: security-team
classification: internal
purpose: Reduce time to remediate known vulnerabilities in internal repositories.
risk:
level: medium
category:
- security
spec:
triggers:
- type: manual
inputs:
- name: repository
type: string
required: true
description: Repository in the form owner/name.
- name: cve
type: string
required: true
pattern: "^CVE-[0-9]{4}-[0-9]{4,}$"
budget:
maxCostUsd: 2.00
maxSteps: 30
maxDuration: 15m
resources:
maxTokens: 400000
maxToolCalls: 60
maxRetries: 2
maxConcurrency: 1
secrets:
- name: GITHUB_TOKEN
source: secret-manager
scope:
- github
mcpServers:
- name: github
transport: streamable-http
url: https://mcp.example.com/github
auth:
secretRef: GITHUB_TOKEN
actionGroups:
github.read:
- github.search_code
- github.get_file_contents
github.write:
- github.create_branch
- github.push_files
- github.create_pull_request
- github.merge_pull_request
git.push:
- github.push_files
pullRequest.create:
- github.create_pull_request
git.merge:
- github.merge_pull_request
agents:
- id: researcher
model:
provider: anthropic
name: claude
instructions: |
Find where the vulnerable dependency or code path is used and summarize
the affected files and the recommended fix.
tools:
- type: mcp
server: github
tools:
- search_code
- get_file_contents
- id: fixer
model:
provider: ollama
name: qwen3
instructions: |
Apply the recommended fix with the smallest possible change.
tools:
- type: mcp
server: github
workflow:
- id: investigate
agent: researcher
task: "Investigate ${{ inputs.cve }} in ${{ inputs.repository }}."
outputs:
- name: report
classification: internal
- id: fix
agent: fixer
task: "Fix the issue described in the report: ${{ steps.investigate.outputs.report }}"
dependsOn:
- investigate
- id: test
type: command
command: npm test
image: registry.example.com/build/node@sha256:3f1d5c0a9e2b7c4d6e8f0a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f
timeout: 10m
dependsOn:
- fix
permissions:
default: deny
tools:
github.read:
allow: true
github.write:
allow: true
resources:
- "${{ inputs.repository }}"
shell.execute:
allow: true
production.deploy:
allow: false
network:
egress: deny
allowHosts:
- mcp.example.com
- registry.npmjs.org
policies:
git:
allowPush: true
allowForcePush: false
pullRequest:
allowCreate: true
merge:
allow: false
production:
allow: false
audit:
enabled: true
  • metadata: name, version, owner.team, classification and a risk level. These are required by the governance profile.
  • spec.inputs: repository and cve, validated before the run; cve must match a pattern.
  • spec.budget: at most $2.00, 30 steps and 15 minutes, plus token, tool-call, retry and concurrency limits.
  • spec.secrets and spec.mcpServers: the GitHub token is only referenced by secretRef.
  • spec.agents: a researcher with read-only tools and a fixer with the GitHub tools.
  • spec.workflow: investigate, fix (depends on investigate) and a test command step with a digest-pinned image.
  • spec.permissions: default deny; production deployment is explicitly denied; network egress is limited to two hosts.
  • spec.policies: shorthands that allow push and pull requests but forbid force-push, merge and production.

See Workflow steps, Tool governance and Budgets.