community-automations/security-auditor

DevOps y Código

PublicSubagente de Claude

Auditor de seguridad

Los escáneres de seguridad producen una lista larga una vez y luego se ignoran porque nadie tiene tiempo de separar la señal del ruido. Este auditor corre cada semana y actúa sobre lo que encuentra.

sonnet1 semanaTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Por qué este subagente

Los escáneres de seguridad producen una lista larga una vez y luego se ignoran porque nadie tiene tiempo de separar la señal del ruido. Este auditor corre cada semana y actúa sobre lo que encuentra.

Escanea dependencias e infraestructura como código, ordena los hallazgos por severidad y explotabilidad real, y redacta una solución por cada problema prioritario. Recibes pull requests priorizadas y un breve resumen de lo que necesita el visto bueno, así el backlog se reduce en vez de crecer hasta ser un informe que nadie lee.

Cómo se ejecuta

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Salida de ejemplo

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.