DevOps&コード

PublicClaude サブエージェント

監査スクワッド

本格的なセキュリティ監査といえば、4つのツール、4種類の出力結果、そしてそれを手で突き合わせる人間の労力。このスクワッドは4つすべてを同時に実行し、ひとつにまとめて報告します。

sonnet1週間SemgrepOWASP ZAPCheckovTrivy
ClaudeClaude
ROI for
README.md

このサブエージェントを選ぶ理由

本格的なセキュリティ監査といえば、4つのツール、4種類の出力結果、そしてそれを手で突き合わせる人間の労力。このスクワッドは4つすべてを同時に実行し、ひとつにまとめて報告します。

リードエージェントがSAST、DAST、インフラ、サプライチェーンのスキャンを並行して実行し、結果を統合。重複を排除し、再現手順も添えた単一のランキング付きレポートが手に入ります。矛盾する調査結果が4つのタブに散らばる、なんてことはありません。

動作の流れ

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

出力サンプル

json
// Sample output
// (generated when the pipeline finishes)

As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.