community-automations/security-auditor

DevOps & Κώδικας

PublicΥποπράκτορας Claude

Ελεγκτής Ασφαλείας

Οι σαρωτές ασφαλείας βγάζουν μια τεράστια λίστα μία φορά και μετά τους αγνοούν γιατί κανείς δεν έχει χρόνο να ξεχωρίσει το ουσιαστικό από τον θόρυβο. Αυτός ο auditor τρέχει εβδομαδιαία και δρα σε ό,τι βρίσκει.

sonnet1 εβδομάδαTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Γιατί αυτός ο subagent

Οι σαρωτές ασφαλείας βγάζουν μια τεράστια λίστα μία φορά και μετά τους αγνοούν γιατί κανείς δεν έχει χρόνο να ξεχωρίσει το ουσιαστικό από τον θόρυβο. Αυτός ο auditor τρέχει εβδομαδιαία και δρα σε ό,τι βρίσκει.

Σαρώνει dependencies και infrastructure code, κατατάσσει τα ευρήματα κατά σοβαρότητα και πραγματική εκμεταλλευσιμότητα, και συντάσσει διόρθωση για κάθε υψηλής προτεραιότητας θέμα. Λαμβάνεις pull requests με προτεραιότητα και μια σύντομη σύνοψη όσων χρειάζονται έγκριση, ώστε το backlog μικραίνει αντί να γίνεται μια αναφορά που κανείς δεν διαβάζει.

Πώς λειτουργεί

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Δείγμα εξόδου

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.