community-automations/security-auditor

DevOps e Código

PublicSubagente Claude

Auditor de Segurança

Os scanners de segurança produzem uma lista longa uma vez e depois são ignorados porque ninguém tem tempo para separar o sinal do ruído. Este auditor corre semanalmente e atua sobre o que encontra.

sonnet1 semanaTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Porquê este subagente

Os scanners de segurança produzem uma lista longa uma vez e depois são ignorados porque ninguém tem tempo para separar o sinal do ruído. Este auditor corre semanalmente e atua sobre o que encontra.

Analisa as dependências e o código de infraestrutura, ordena os resultados por severidade e explorabilidade real e esboça uma correção para cada problema de alta prioridade. Recebe pull requests priorizados e um breve resumo do que precisa de aprovação, para que o backlog encolha em vez de crescer até virar um relatório que ninguém lê.

Como funciona

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Saída de exemplo

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.