community-automations/security-auditor

DevOps ve Kod

PublicClaude otomasyonu

Güvenlik Denetleyicisi

Güvenlik tarayıcıları bir kez uzun bir liste üretir, sonra göz ardı edilir; çünkü kimsenin sinyali gürültüden ayıracak vakti yoktur. Bu denetçi haftalık çalışır ve bulduğu şey üzerine hareket eder.

sonnet1 haftaTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Bu otomasyon neden işinize yarar

Güvenlik tarayıcıları bir kez uzun bir liste üretir, sonra göz ardı edilir; çünkü kimsenin sinyali gürültüden ayıracak vakti yoktur. Bu denetçi haftalık çalışır ve bulduğu şey üzerine hareket eder.

Bağımlılıkları ve altyapı kodunu tarar, bulguları ciddiyete ve gerçek istismar edilebilirliğe göre sıralar ve öncelikli her sorun için bir düzeltme taslağı çıkarır. Öncelik sırasına dizilmiş pull request'ler ve onay gereken konuların kısa bir özetini alırsınız; böylece birikmiş işler, kimsenin okumadığı bir rapora dönüşmek yerine küçülür.

Nasıl çalışır

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Örnek çıktı

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.