community-automations/security-auditor

DevOps e codice

PublicSubagent Claude

Auditor di sicurezza

Gli scanner di sicurezza producono una lunga lista una volta sola e poi vengono ignorati, perché nessuno ha il tempo di separare il segnale dal rumore. Questo auditor gira ogni settimana e agisce su ciò che trova.

sonnet1 settimanaTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Perché questo subagent

Gli scanner di sicurezza producono una lunga lista una volta sola e poi vengono ignorati, perché nessuno ha il tempo di separare il segnale dal rumore. Questo auditor gira ogni settimana e agisce su ciò che trova.

Analizza dipendenze e codice infrastrutturale, ordina i risultati per gravità e reale sfruttabilità e prepara una correzione per ogni problema ad alta priorità. Ottieni pull request ordinate per priorità e un breve riepilogo di ciò che serve approvare, così il backlog si riduce invece di gonfiarsi in un report che nessuno legge.

Come gira

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Esempio di output

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.