DevOps e codice

PublicSubagent Claude

Squadra di audit

Un audit di sicurezza serio significa quattro strumenti diversi, quattro serie di output e una persona che cerca di riconciliarli a mano. Questa squadra li esegue tutti e quattro insieme e riferisce come un'unica voce.

sonnet1 settimanaSemgrepOWASP ZAPCheckovTrivy
ClaudeClaude
ROI for
README.md

Perché questo subagent

Un audit di sicurezza serio significa quattro strumenti diversi, quattro serie di output e una persona che cerca di riconciliarli a mano. Questa squadra li esegue tutti e quattro insieme e riferisce come un'unica voce.

L'agent capofila dispaccia in parallelo gli scan SAST, DAST, infrastruttura e supply-chain, poi unisce i risultati. Ottieni un unico report ordinato con i duplicati rimossi e le note di riproduzione, invece di quattro schede con risultati in conflitto.

Come gira

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Esempio di output

json
// Sample output
// (generated when the pipeline finishes)

As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.