Prawdziwy audyt bezpieczeństwa to cztery różne narzędzia, cztery zestawy wyników i człowiek próbujący ręcznie je pogodzić. Ten zespół uruchamia wszystkie cztery naraz i raportuje jako jeden.
sonnet1 tydzieńSemgrepOWASP ZAPCheckovTrivy
Claude
92ROI
78Scale
$4.6k92Saved
ROI for
README.md
Dlaczego ten subagent
Prawdziwy audyt bezpieczeństwa to cztery różne narzędzia, cztery zestawy wyników i człowiek próbujący ręcznie je pogodzić. Ten zespół uruchamia wszystkie cztery naraz i raportuje jako jeden.
Główny agent równolegle uruchamia skany SAST, DAST, infrastruktury i łańcucha dostaw, a następnie łączy wyniki. Otrzymujesz jeden rankingowy raport z usuniętymi duplikatami i notatkami odtworzeniowymi, zamiast czterech zakładek ze sprzecznymi wynikami.
Jak działa
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
Każdy pracownik przeprowadza swój skan równolegle: analizę kodu źródłowego, aktywne testowanie, przegląd konfiguracji infrastruktury oraz CVE zależności.
pending
Znaleziska są deduplikowane i oceniane pod kątem poważności oraz możliwości eksploatacji we wszystkich czterech strumieniach.
pending
Agent lider kompiluje jeden posortowany raport z notatkami dotyczącymi reprodukcji błędów i otwiera zgłoszenia (issues) dla elementów o wysokiej ważności.
pending
Przykładowe wyjście
json
// Sample output
// (generated when the pipeline finishes)
As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.