community-automations/security-auditor

DevOps & 코드

PublicClaude 서브에이전트

보안 감사관

보안 스캐너는 한 번 긴 목록을 쏟아내고, 시그널과 노이즈를 분류할 시간이 없어서 그대로 방치됩니다. 이 감사 도구는 매주 실행되며 발견한 것에 실제로 조치합니다.

sonnet1주TrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

왜 이 서브에이전트인가

보안 스캐너는 한 번 긴 목록을 쏟아내고, 시그널과 노이즈를 분류할 시간이 없어서 그대로 방치됩니다. 이 감사 도구는 매주 실행되며 발견한 것에 실제로 조치합니다.

의존성과 인프라 코드를 스캔하고, 심각도와 실제 악용 가능성 기준으로 결과를 순위화하며, 높은 우선순위 이슈마다 수정안을 작성합니다. 우선순위가 매겨진 풀 리퀘스트와 승인만 남았다는 짧은 요약을 받으므로, 백로그는 줄어드는 것이지 아무도 읽지 않는 리포트로 쌓이는 것이 아닙니다.

작동 방식

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

샘플 출력

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.