보안 스캐너는 한 번 긴 목록을 쏟아내고, 시그널과 노이즈를 분류할 시간이 없어서 그대로 방치됩니다. 이 감사 도구는 매주 실행되며 발견한 것에 실제로 조치합니다.
sonnet1주TrivyCheckovGitHubSlack
Claude
96ROI
80Scale
$4.8k93Saved
ROI for
README.md
왜 이 서브에이전트인가
보안 스캐너는 한 번 긴 목록을 쏟아내고, 시그널과 노이즈를 분류할 시간이 없어서 그대로 방치됩니다. 이 감사 도구는 매주 실행되며 발견한 것에 실제로 조치합니다.
의존성과 인프라 코드를 스캔하고, 심각도와 실제 악용 가능성 기준으로 결과를 순위화하며, 높은 우선순위 이슈마다 수정안을 작성합니다. 우선순위가 매겨진 풀 리퀘스트와 승인만 남았다는 짧은 요약을 받으므로, 백로그는 줄어드는 것이지 아무도 읽지 않는 리포트로 쌓이는 것이 아닙니다.
작동 방식
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
결과를 상관관계 분석하고 중복을 제거한 뒤, 심각도와 실제 공격 가능성에 따라 순위를 매깁니다.
pending
높은 우선순위의 이슈(예: 버전 업그레이드 또는 IaC 규칙 수정)에 대한 수정안을 초안 작성합니다.
pending
우선순위 기반 풀 리퀘스트를 열고, 인간 승인 대상 항목에 대한 요약을 전송합니다.
pending
샘플 출력
json
// Sample output
// (generated when the pipeline finishes)
Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.