community-automations/security-auditor

DevOps 與程式碼

PublicClaude 子代理

安全稽核工具

安全掃描工具產生一份長長的清單,然後就再也沒人看了,因為沒人有力氣從噪音裡挑出真正重要的事。這個稽核工具每週自動執行,而且會針對發現的問題採取行動。

sonnet1 週TrivyCheckovGitHubSlack
ClaudeClaude
ROI for
README.md

為什麼選擇此子代理

安全掃描工具產生一份長長的清單,然後就再也沒人看了,因為沒人有力氣從噪音裡挑出真正重要的事。這個稽核工具每週自動執行,而且會針對發現的問題採取行動。

它會掃描相依套件和基礎設施程式碼,依嚴重程度和實際可利用性排序,並為每個高優先級問題草擬修正方案。你會收到按優先級排序的 pull request,以及一份簡短的摘要說明哪些需要你核准——待辦清單因此越來越短,而不是堆成一份沒人讀的報告。

運作方式

    • Read

      Used at step 01 to kick off the pipeline.

    • Write

      Used at step 01 to kick off the pipeline.

    • WebFetch

      Used at step 01 to kick off the pipeline.

    • WebSearch

      Used at step 01 to kick off the pipeline.

輸出範例

json
// Sample output
// (generated when the pipeline finishes)

Given weekly SCA and IaC scan results, return a ranked findings list with a drafted fix PR for each high-priority issue and a sign-off summary.

Unlock the rest

The full agent definition, install snippet, and starter task are gated for community members.

Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.