Security
Dependency CVE Burndown
Rank vulnerabilities by real exposure, then fix the reachable ones first.
Use when
Scanners are noisy and you need to know what is actually reachable.
Cadence
After security scan
Verification
No exploitable high or critical CVE remains without an explicit risk decision.
Structured loop spec
| Field | Value |
|---|---|
| Name | Dependency CVE Burndown |
| Category | Security |
| Trigger | After security scan |
| Objective | Rank vulnerabilities by real exposure, then fix the reachable ones first. |
| Allowed inputs | Relevant files, source notes, logs, tests, screenshots, metrics, or task state for this loop |
| Allowed actions | Define the exact scope, source of truth, and approval boundary.; Inspect current state and rank the highest-risk gap.; Make one small, reversible improvement.; Run the stated verification and record evidence.; Stop on success, budget, no progress, or approval required. |
| Verification | No exploitable high or critical CVE remains without an explicit risk decision. |
| Stop condition | Stop when the verifier passes, the budget is exhausted, no progress is made, a blocker appears, or approval is required. |
| Budget | Set a time, turn, token, retry, file, or dollar cap before running the loop. |
| Approval boundary | Human approval required before publishing, sending, deleting, spending, changing accounts, touching production, or making reputational/legal/financial commitments. |
| Safe output | Draft, report, checklist, table, or approval-gated recommendation |
| Works with | Claude, ChatGPT, Gemini, any tool-using AI assistant |
Steps
- Define the exact scope, source of truth, and approval boundary.
- Inspect current state and rank the highest-risk gap.
- Make one small, reversible improvement.
- Run the stated verification and record evidence.
- Stop on success, budget, no progress, or approval required.
Prompt
Run the Dependency CVE Burndown loop. Use it when Scanners are noisy and you need to know what is actually reachable. Work in bounded iterations: inspect current state, choose the highest-risk gap, make one reversible improvement, verify it, and record evidence. Stop when No exploitable high or critical CVE remains without an explicit risk decision. or when blocked, budget exhausted, or approval is required.Run in Claude Code
Paste this into Claude Code (or any tool-using agent) to run the loop bounded: one change per round, the same verification every round, durable state files, and explicit stop conditions.
Run the "Dependency CVE Burndown" loop from AI Loop Library (https://ailooplibrary.com/loops/dependency-cve-burndown/) as a bounded loop.
Goal: Rank vulnerabilities by real exposure, then fix the reachable ones first.
Rules: one change per round; run the same verification every round (No exploitable high or critical CVE remains without an explicit risk decision.); append each round to docs/loops/dependency-cve-burndown/progress.md and update docs/loops/dependency-cve-burndown/state.json; stop on verifier pass, 8 rounds, 3 consecutive failed verifications, no progress, a blocker, or anything needing human approval (money, production, outbound, deletion). Finish with a proof report: rounds used, changes made, verification output, remaining risk, and the next human decision.