community-automations/security-auditor

DevOps a kód

PublicSubagent Claude

Bezpečnostní auditor

Bezpečnostní skenery jednou vygenerují dlouhý seznam a pak se ignorují, protože nikdo nemá čas oddělit podstatné od šumu. Tento auditor běží týdně a jedná podle toho, co najde.

sonnet1 týdenTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Proč tento subagent

Bezpečnostní skenery jednou vygenerují dlouhý seznam a pak se ignorují, protože nikdo nemá čas oddělit podstatné od šumu. Tento auditor běží týdně a jedná podle toho, co najde.

Skenuje závislosti a kód infrastruktury, řadí nálezy podle závažnosti a skutečné zneužitelnosti a pro každý prioritní problém navrhne opravu. Dostanete seřazené pull requesty a krátké shrnutí toho, co potřebuje schválení, takže se backlog zmenšuje, místo aby rostl v report, který nikdo nečte.

Jak běží

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Ukázkový výstup

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.