---
title: "cx-findings-to-fix"
description: "Findings-to-Fix builds on Checkmarx One Triage Assist and Remediation Assist. Triage Assist has already evaluated the findings on the platform using Attackability-based context (reachability, exploitability, code context"
canonical: https://agentpluginsdirectory.com/plugins/cx-findings-to-fix
last-updated: 2026-10-11
---

# cx-findings-to-fix
Findings-to-Fix builds on Checkmarx One Triage Assist and Remediation Assist. Triage Assist has already evaluated the findings on the platform using Attackability-based context (reachability, exploitability, code context, policy) and confirmed the ones that require action. The plugin takes only those confirmed findings, asks Remediation Assist to generate the review-ready fix, and brings it into the developer's editor. The agent proposes; the developer approves. Pulls only the findings Triage Assist has confirmed on the current branch, requests fixes from Remediation Assist, and proposes them in VS Code as edits with Keep and Undo. A skill, a custom agent, and a zero-dependency tool (Python or Node) against the Checkmarx One API.
- Slug: cx-findings-to-fix
- Publisher: cx-israel-ogunsakin
- Repository: https://github.com/cx-israel-ogunsakin/cx-findings-to-fix
- Manifest: plugin.json
- Version: 1.6.0
- Category (editorial): security
- Skills: 1 (fix-confirmed-findings)
- MCP servers: 0
- Stars: 0
- Repository created: 2026-08-17
- Repository last pushed: 2026-08-27
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/cx-findings-to-fix
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What cx-findings-to-fix does, in the publisher's words

Built on Checkmarx One Triage Assist and Remediation Assist, working inside VS Code through GitHub Copilot. Triage Assist has already evaluated the findings on the platform using Attackability-based context (reachability, exploitability, code context, policy signals) and confirmed the ones that require action. The plugin takes only those confirmed findings, asks Remediation Assist to generate the review-ready fix, and shows you each change to Keep or Undo. The agent proposes; you approve.

You ask Copilot to fix your findings. It pulls only the findings Triage Assist has confirmed, asks Remediation Assist for the fix, and shows you the change. That is the whole thing.

Using Claude Code instead? Use cx-findings-to-fix-claude, the Claude Code version of this same plugin.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/cx-israel-ogunsakin/cx-findings-to-fix/HEAD/README.md

## Skills

- fix-confirmed-findings: Find and fix the Checkmarx One security findings that Triage Assist has confirmed on this repo's branch, with fixes generated by Checkmarx Remediation Assist and applied as editor edits you keep or undo. Use whenever the developer mentions Checkmarx, security findings, vulnerabilities, scan results…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
