OpenText’s Fortify Agent Skills give coding agents access to security findings and defined workflows, so they can prepare fixes with more context than source code alone. The important boundary: an agent can propose the repair without becoming the authority that signs it off. For teams already letting agents change repositories, that is a useful distinction. Giving the builder a better inspection report need not mean letting it award its own safety certificate.
OpenText Watch analysis
What happened
In a 1 October post, OpenText’s Dan Cogburn describes open-source Agent Skills covering security scanning, vulnerability triage, remediation, dependency upgrades and integration with development pipelines. The post identifies support for Claude Code, OpenAI Codex, Gemini CLI, GitHub Copilot and other compatible agents.
Depending on the chosen skill and configured Fortify environment, an agent can retrieve findings, follow defined analysis steps and prepare remediation changes for developer review. Fortify supplies the security context; the coding agent does not become the system of record.
The testing tools have separate jobs. Static application security testing examines source code, dynamic testing probes running applications and APIs, and software composition analysis checks open-source components for vulnerabilities, licence obligations and component-health risks.
Cogburn also describes Remediation Aviator as an AI-assisted auditing and remediation tool for static-analysis findings. Its ability to apply fixes automatically to eligible findings is distinct from the Agent Skills workflow for preparing changes for review.
Why it matters
An agent asked to fix a security problem from code alone must infer what matters. Supplying an existing finding and a defined workflow gives it a more concrete task: address this identified issue, then return the proposed change for scrutiny.
That separation matters as agents gain the ability to call tools and complete multi-step development tasks. A plausible patch is not the same thing as an accepted exception, an approved release or evidence that the vulnerability has gone away.
Our read
The useful idea here is not another promise that AI will make software secure. It is a workable division of labour: established testing finds issues, agents help prepare changes, and the organisation retains control over consequential decisions.
Cogburn’s four-part operating model is worth taking into a team discussion: test across the software lifecycle; give agents approved security context and workflows; retain human review, policy, evidence and reporting; and use AI-assisted auditing and remediation where it reduces manual work without surrendering control.
For Fortify users, start by choosing a supported workflow and deciding what the agent may prepare, what requires review and which test must pass afterwards. The post describes capabilities and guidance, not measured results showing that Agent Skills improve fix accuracy.
What to watch
- Whether teams publish results on accepted fixes, rejected patches and vulnerabilities that survive remediation.
- How organisations enforce the boundary between proposing a change and approving it.
- Whether support across different coding agents produces consistent review evidence rather than different flavours of paperwork.
Discussion spark: Should a coding agent that prepares a security fix be allowed to run its acceptance checks, provided a person approves the change, or should validation always use a separately controlled workflow?
Sources and evidence
- Source update (1 October 2026, 13:00 UTC)
not affiliated with or endorsed by OpenText