community-automations/security-auditor

DevOps & Mã nguồn

PublicSubagent Claude

Trình kiểm toán bảo mật

Các trình quét bảo mật tạo ra một danh sách dài rồi bị bỏ xó vì chẳng ai có thời gian phân biệt đâu là tín hiệu, đâu là nhiễu. Trình audit này chạy hàng tuần và hành động dựa trên những gì nó tìm thấy.

sonnet1 tuầnTrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

Tại sao chọn subagent này

Các trình quét bảo mật tạo ra một danh sách dài rồi bị bỏ xó vì chẳng ai có thời gian phân biệt đâu là tín hiệu, đâu là nhiễu. Trình audit này chạy hàng tuần và hành động dựa trên những gì nó tìm thấy.

Nó quét dependency và code hạ tầng, xếp hạng các phát hiện theo mức độ nghiêm trọng và khả năng bị khai thác thực tế, rồi soạn sẵn bản fix cho từng vấn đề ưu tiên cao. Bạn nhận được các pull request đã xếp thứ tự ưu tiên cùng bản tóm tắt ngắn những gì cần phê duyệt — backlog cứ thế nhỏ dần thay vì phình thành một bản báo cáo chẳng ai đọc.

Cách vận hành

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

Ví dụ đầu ra

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.