autofix
GitHub auto-fix bot — generate, approve, and reject patches that get pushed as PRs (tier-gated).
List auto-fix proposals for this scan, newest first.
List auto-fix proposals for this scan, newest first.
Generate an auto-fix proposal on demand.
Runs the restricted agent (read-only tools, file deny-list, size cap) against the finding and stages a proposal. If an `open` proposal already exists for the same fingerprint+repo, that one is returned with `200` instead — idempotent on the dev-tool path, so a CI loop can safely retry.
Push the proposal as a GitHub PR via the shared ZeroQuarryBot App.
Runs the layered safety stack before the network call:
Reject a staged proposal. Not tier-gated.
Reject a staged proposal. Not tier-gated.