community-automations/security-auditor

DevOps & code

PublicClaude-subagent

Security-auditor

Security-scanners produceren eenmaal een lange lijst en worden daarna genegeerd omdat niemand tijd heeft om signaal van ruis te scheiden. Deze auditor draait wekelijks en handelt naar wat hij vindt.

sonnet1 weekTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Waarom deze subagent

Security-scanners produceren eenmaal een lange lijst en worden daarna genegeerd omdat niemand tijd heeft om signaal van ruis te scheiden. Deze auditor draait wekelijks en handelt naar wat hij vindt.

Het scant dependencies en infrastructuurcode, rangschikt bevindingen op ernst en reële exploiteerbaarheid, en stelt per hoog-prioritair probleem een fix op. Je krijgt geprioriteerde pull requests en een korte samenvatting van wat goedkeuring nodig heeft, zodat de backlog krimpt in plaats van uit te groeien tot een rapport dat niemand leest.

Hoe hij werkt

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Voorbeelduitvoer

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.