SkillByAIOpen interactive version →

Lesson 25 / 25

A Safe Auto-Fix Checklist

Before turning the bot on.

Ten questions

Is the task type well suited (clear check, small change)? Does every fix start with a failing reproduction test? Is context focused and are constraints stated? Are candidates verified in isolated sandboxes with the full suite, lint, types and scans? Are flaky tests detected first? Are tests strong at the changed lines? Are test files and other protected paths read-only for the bot? Are secrets scanned and the fixer kept away from real credentials? Does the bot have least-privilege tokens with branch protection and human review? Are reverts easy and metrics tracked?

The checklist

Use it for every repository you enable.

[ ] task types limited to objectively checkable, small changes
[ ] failing reproduction test required before any fix
[ ] focused context + explicit constraints
[ ] isolated sandbox per candidate; full suite + lint + types + scans
[ ] flaky-test detection before fixing
[ ] boundary / mutation checks on changed lines
[ ] tests and protected paths read-only; diff size limit
[ ] secret scanning; no production credentials in the sandbox
[ ] least-privilege bot token; branch protection; human approval
[ ] one fix per commit; revert path; metrics dashboard

Roll out repository by repository

Enable the bot on one well-tested repository, measure, then expand.

Quick check: Which item belongs on a safe auto-fix checklist?

  • Production credentials in the sandbox
  • The bot can merge to main without review
  • Test files are read-only for the bot
  • Skip the full test suite to save time
Answer

Test files are read-only for the bot — Constrain, verify, review.