[nexa] Are AI-Generated Fixes Secure? Analyzing LLM and Agent Patches on SWE-bench