community-automations/security-auditor

DevOps والكود

Publicوكيل Claude فرعي

مدقّق الأمن

ماسحات الأمان تنتج قائمة طويلة مرّة واحدة ثم تُهمَل، لأن لا أحد يملك وقتاً لفرز الإشارة عن الضجيج. هذا المدقّق يعمل أسبوعياً ويتصرّف بما يجده.

sonnetأسبوع واحدTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

لماذا هذا الوكيل تحديدًا

ماسحات الأمان تنتج قائمة طويلة مرّة واحدة ثم تُهمَل، لأن لا أحد يملك وقتاً لفرز الإشارة عن الضجيج. هذا المدقّق يعمل أسبوعياً ويتصرّف بما يجده.

يمسح الاعتماديات وكود البنية التحتية، يرتّب النتائج حسب الخطورة والقابلية الحقيقية للاستغلال، ويصوغ إصلاحاً لكل مشكلة عالية الأولوية. تحصل على pull requests مرتّبة بالأولوية وملخّص قصير لما يحتاج اعتماداً؛ فيتقلّص جدول المهام بدل أن يتضخّم في تقرير لا يقرأه أحد.

كيف يعمل

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

نموذج للمخرجات

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.