Pořádný bezpečnostní audit znamená čtyři různé nástroje, čtyři sady výstupů a člověka, který se je snaží ručně dát dohromady. Tenhle tým spustí všechny čtyři najednou a reportuje jako jeden.
sonnet1 týdenSemgrepOWASP ZAPCheckovTrivy
Claude
92ROI
78Scale
$4.6k92Saved
ROI for
README.md
Proč tento subagent
Pořádný bezpečnostní audit znamená čtyři různé nástroje, čtyři sady výstupů a člověka, který se je snaží ručně dát dohromady. Tenhle tým spustí všechny čtyři najednou a reportuje jako jeden.
Vedoucí agent paralelně rozešle SAST, DAST, sken infrastruktury a supply chainu a pak výsledky sloučí. Dostanete jeden seřazený report bez duplicit a s poznámkami k reprodukování, místo čtyř záložek s protichůdnými nálezy.
Jak běží
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
Každý pracovník spustí svůj sken paralelně: analýzu zdrojového kódu, živé testování, revizi konfigurace infrastruktury a zranitelnosti závislostí (CVE).
pending
Zjištění jsou deduplikována a hodnocena podle závažnosti a možnosti exploitace napříč všemi čtyřmi proudy.
pending
Vedoucí agent sestaví jeden řazený report s poznámkami pro reprodukci problémů a otevře issues pro položky s vysokým závažností.
pending
Ukázkový výstup
json
// Sample output
// (generated when the pipeline finishes)
As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.