community-automations/security-auditor

DevOps&コード

PublicClaude サブエージェント

セキュリティ監査員

セキュリティスキャナーは一度長いリストを出力したきり、ノイズから本当に必要な情報を見分ける時間が誰にもないため、無視されがちです。この監査ツールは毎週実行され、検出した問題に対応します。

sonnet1週間TrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

このサブエージェントを選ぶ理由

セキュリティスキャナーは一度長いリストを出力したきり、ノイズから本当に必要な情報を見分ける時間が誰にもないため、無視されがちです。この監査ツールは毎週実行され、検出した問題に対応します。

依存関係とインフラコードをスキャンし、重大度と実際の悪用可能性で検出結果をランク付けし、優先度の高い問題ごとに修正のドラフトを作成します。優先順位付けされたプルリクエストと承認が必要な項目の短いサマリーが届くため、バックログは誰も読まないレポートに膨れ上がるのではなく、着実に縮小していきます。

動作の流れ

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

出力サンプル

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.