# Arn Code Batch Cve Fix

> - This skill should be used when the user says "fix CVEs", "patch vulnerabilities", "apply security patches", "resolve security advisories", "batch CVE fix", "patch dependencies", "fix security findings", "remediate CVEs", "apply CVE fixes", "batch fix vulnerabilities", "resolve vulnerability tickets", "arness CVE fix", "arn-code-batch-cve-fix", "fix all open CVE tickets", "cleanup resolved CVE proposals", or wants Arness to apply per-group dependency bumps for previously-triaged CVEs and open per-group pull requests that close their corresponding sub-issues. Reuses arn-code-batch-implement worker isolation verbatim, opens PRs targeting the configured Security branch, and offers an interactive post-merge cleanup of fully-resolved past CVE proposals. Interactive only — no proposal mode, no headless write path; every PR is human-reviewed and every archive move is confirmed via AskUserQuestion. Requires that arn-code-batch-cve-scan has produced triage records and sub-issues.

## Facts
- Page: https://tashan.sh/capability/skill-appsvortex-arn-code-batch-cve-fix
- tashan id: skill:AppsVortex/arn-code-batch-cve-fix
- Source: https://github.com/AppsVortex/arness
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: not measured
- Freshness: not measured
- Evidence coverage: not measured
- Health: not measured
- Instruction depth: not yet graded
- Official: no

## Install

```sh
cp -r arn-code-batch-cve-fix ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-05 by tashan (https://tashan.sh) from public evidence. Scorer s5.
