community-automations/security-auditor

DevOps і код

PublicСубагент Claude

Аудитор безпеки

Сканери безпеки один раз видають довгий список, а потім їх ігнорують, бо ні в кого немає часу відділяти сигнал від шуму. Цей аудитор працює щотижня й діє на основі знайденого.

sonnet1 тижденьTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Чому цей субагент

Сканери безпеки один раз видають довгий список, а потім їх ігнорують, бо ні в кого немає часу відділяти сигнал від шуму. Цей аудитор працює щотижня й діє на основі знайденого.

Він сканує залежності та інфраструктурний код, ранжує знахідки за серйозністю та реальною експлуатованістю і готує виправлення для кожної високопріоритетної проблеми. Ви отримуєте пріоритизовані пул-реквести та короткий звіт про те, що потребує погодження, тож беклог скорочується, а не перетворюється на звіт, який ніхто не читає.

Як він працює

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Приклад результату

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.