تدقيق أمني حقيقي يعني أربع أدوات مختلفة، وأربع مجموعات مخرجات، وشخصاً يحاول التوفيق بينها يدوياً. هذا الفريق يشغّل الأربع دفعةً واحدة، ويُبلِغ كجهة واحدة.
sonnetأسبوع واحدSemgrepOWASP ZAPCheckovTrivy
Claude
92ROI
78Scale
$4.6k92Saved
ROI for
README.md
لماذا هذا الوكيل تحديدًا
تدقيق أمني حقيقي يعني أربع أدوات مختلفة، وأربع مجموعات مخرجات، وشخصاً يحاول التوفيق بينها يدوياً. هذا الفريق يشغّل الأربع دفعةً واحدة، ويُبلِغ كجهة واحدة.
يُطلِق الوكيل القائد فحوص SAST وDAST والبنية التحتية وسلسلة التوريد بالتوازي، ثم يدمج النتائج. تحصل على تقرير واحد مرتّب بلا تكرار ومع ملاحظات إعادة إنتاج، بدل أربع نوافذ من نتائج متضاربة.
كيف يعمل
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
يشغّل كل عامل فحصه بالتوازي: تحليل المصدر، والاستكشاف الحيّ، ومراجعة إعداد البنية التحتية، وثغرات CVE في الاعتماديات.
pending
تُزال النتائج المكرّرة وتُسجَّل بدرجات حسب الخطورة والقابلية للاستغلال عبر التدفّقات الأربعة.
pending
يجمّع الوكيل القائد تقريراً واحداً مرتّباً مع ملاحظات إعادة الإنتاج، ويفتح قضايا للبنود عالية الخطورة.
pending
نموذج للمخرجات
json
// Sample output
// (generated when the pipeline finishes)
As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.