DevOps 與程式碼

PublicClaude 子代理

審計小組

一場真正的安全稽核,代表四種不同的工具、四份輸出,還有一個得親手把它們兜在一起的人。這個小隊一次跑完四種掃描,並整合成一份報告。

sonnet1 週內交付SemgrepOWASP ZAPCheckovTrivy
ClaudeClaude
ROI for
README.md

為什麼選擇此子代理

一場真正的安全稽核,代表四種不同的工具、四份輸出,還有一個得親手把它們兜在一起的人。這個小隊一次跑完四種掃描,並整合成一份報告。

主導代理人同步執行 SAST、DAST、基礎設施與供應鏈掃描,再合併結果。你拿到的是一份排序清楚的單一報告,已去除重複項目並附上重現步驟,而不是四個分頁裡互相矛盾的發現。

運作方式

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

輸出範例

json
// Sample output
// (generated when the pipeline finishes)

As the lead agent, run SAST, DAST, IaC, and supply-chain sub-agents in parallel, then merge their findings into a single deduplicated report ranked by severity with reproduction steps.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.