Loop Cve Audit

Iterative dependency-CVE remediation loop: scan with ecosystem-native advisory tooling, assess whether each high/critical finding is actually reachable (with call-path evidence, not vibes), fix the highest-risk reachable one with the smallest credible change, re-verify, and repeat. Terminates when no exploitable high/critical CVE remains or every remaining finding has an evidence-backed reachability assessment and an approved risk decision. Use when the user mentions CVEs, vulnerability scanning, dependency security, npm/pip/cargo audit, security patching, or wants a recurring dependency-security loop.

tomimor f0a1ff0 7.9 KB Updated

File contents

tomimor/skills/tree/main/skills/loop-cve-audit commit f0a1ff07cb

Frequently asked questions

npx skillmds@latest add tomimor/loop-cve-audit