DevOps & code

PublicClaude-subagent

Audit-squad

Een echte security-audit betekent vier verschillende tools, vier sets output en een mens die ze met de hand probeert te rijmen. Deze squad draait alle vier tegelijk en rapporteert als één.

sonnet1 weekSemgrepOWASP ZAPCheckovTrivy
ClaudeClaude
ROI for
README.md

Waarom deze subagent

Een echte security-audit betekent vier verschillende tools, vier sets output en een mens die ze met de hand probeert te rijmen. Deze squad draait alle vier tegelijk en rapporteert als één.

De lead-agent waaiert SAST, DAST, infrastructuur en supply-chain parallel uit en voegt dan de resultaten samen. Je krijgt één gerangschikt rapport met duplicaten eruit en reproductienotities, in plaats van vier tabbladen met tegenstrijdige bevindingen.

Hoe hij werkt

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Voorbeelduitvoer

json
// Sample output
// (generated when the pipeline finishes)

As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.