Un audit di sicurezza serio significa quattro strumenti diversi, quattro serie di output e una persona che cerca di riconciliarli a mano. Questa squadra li esegue tutti e quattro insieme e riferisce come un'unica voce.
sonnet1 settimanaSemgrepOWASP ZAPCheckovTrivy
Claude
92ROI
78Scale
$4.6k92Saved
ROI for
README.md
Perché questo subagent
Un audit di sicurezza serio significa quattro strumenti diversi, quattro serie di output e una persona che cerca di riconciliarli a mano. Questa squadra li esegue tutti e quattro insieme e riferisce come un'unica voce.
L'agent capofila dispaccia in parallelo gli scan SAST, DAST, infrastruttura e supply-chain, poi unisce i risultati. Ottieni un unico report ordinato con i duplicati rimossi e le note di riproduzione, invece di quattro schede con risultati in conflitto.
Come gira
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
Ogni worker esegue il suo scan in parallelo: analisi del codice, probing live, revisione della config infrastrutturale e CVE delle dipendenze.
pending
I risultati vengono deduplicati e ordinati per gravità e sfruttabilità su tutti e quattro i flussi.
pending
L'agent capofila compila un unico report ordinato con le note di riproduzione e apre le issue per gli elementi ad alta gravità.
pending
Esempio di output
json
// Sample output
// (generated when the pipeline finishes)
As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.