Security

Dependency CVE Burndown

Rank vulnerabilities by real exposure, then fix the reachable ones first.

Use when

Scanners are noisy and you need to know what is actually reachable.

difficultyAdvanced
categorySecurity
sourceAdapted pattern

Cadence

After security scan

Verification

No exploitable high or critical CVE remains without an explicit risk decision.

Structured loop spec

FieldValue
NameDependency CVE Burndown
CategorySecurity
TriggerAfter security scan
ObjectiveRank vulnerabilities by real exposure, then fix the reachable ones first.
Allowed inputsRelevant files, source notes, logs, tests, screenshots, metrics, or task state for this loop
Allowed actionsDefine the exact scope, source of truth, and approval boundary.; Inspect current state and rank the highest-risk gap.; Make one small, reversible improvement.; Run the stated verification and record evidence.; Stop on success, budget, no progress, or approval required.
VerificationNo exploitable high or critical CVE remains without an explicit risk decision.
Stop conditionStop when the verifier passes, the budget is exhausted, no progress is made, a blocker appears, or approval is required.
BudgetSet a time, turn, token, retry, file, or dollar cap before running the loop.
Approval boundaryHuman approval required before publishing, sending, deleting, spending, changing accounts, touching production, or making reputational/legal/financial commitments.
Safe outputDraft, report, checklist, table, or approval-gated recommendation
Works withClaude, ChatGPT, Gemini, any tool-using AI assistant

Steps

  1. Define the exact scope, source of truth, and approval boundary.
  2. Inspect current state and rank the highest-risk gap.
  3. Make one small, reversible improvement.
  4. Run the stated verification and record evidence.
  5. Stop on success, budget, no progress, or approval required.

Prompt

Run the Dependency CVE Burndown loop. Use it when Scanners are noisy and you need to know what is actually reachable. Work in bounded iterations: inspect current state, choose the highest-risk gap, make one reversible improvement, verify it, and record evidence. Stop when No exploitable high or critical CVE remains without an explicit risk decision. or when blocked, budget exhausted, or approval is required.

Run in Claude Code

Paste this into Claude Code (or any tool-using agent) to run the loop bounded: one change per round, the same verification every round, durable state files, and explicit stop conditions.

Run the "Dependency CVE Burndown" loop from AI Loop Library (https://ailooplibrary.com/loops/dependency-cve-burndown/) as a bounded loop.
Goal: Rank vulnerabilities by real exposure, then fix the reachable ones first.
Rules: one change per round; run the same verification every round (No exploitable high or critical CVE remains without an explicit risk decision.); append each round to docs/loops/dependency-cve-burndown/progress.md and update docs/loops/dependency-cve-burndown/state.json; stop on verifier pass, 8 rounds, 3 consecutive failed verifications, no progress, a blocker, or anything needing human approval (money, production, outbound, deletion). Finish with a proof report: rounds used, changes made, verification output, remaining risk, and the next human decision.

Get the MCP server + agent pack

Tags

CVEdependenciessecurity

Related loops

Browse all 68 loops