community-automations/security-auditor

DevOps i kod

PublicSubagent Claude

Audytor bezpieczeństwa

Skanery bezpieczeństwa generują raz długą listę, a potem są ignorowane, bo nikt nie ma czasu oddzielić sygnału od szumu. Ten audytor działa co tydzień i podejmuje działania na podstawie tego, co znajdzie.

sonnet1 tydzieńTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Dlaczego ten subagent

Skanery bezpieczeństwa generują raz długą listę, a potem są ignorowane, bo nikt nie ma czasu oddzielić sygnału od szumu. Ten audytor działa co tydzień i podejmuje działania na podstawie tego, co znajdzie.

Skanuje zależności i kod infrastruktury, szereguje ustalenia według powagi i realnej możliwości wykorzystania, i przygotowuje poprawkę dla każdego problemu o wysokim priorytecie. Dostajesz spriorytetyzowane pull requesty i krótkie podsumowanie tego, co wymaga akceptacji — dzięki czemu backlog się kurczy, zamiast rozrastać w raport, którego nikt nie czyta.

Jak działa

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Przykładowe wyjście

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.