发布于 2026年8月29日 · 我们于 2026年8月31日 确认该职位仍然有效
US$ 250 – US$ 300 (每个项目)
I need an AI-driven security harness whose single focus is vulnerability scanning. The agent should automatically inspect my codebase, exposed and internal APIs, as well as the cloud configuration that supports them, then flag weaknesses with clear, actionable findings. Here is what matters most to me: • A self-contained module or set of scripts that can be dropped into an existing CI/CD pipeline and triggered on every commit or on demand. • AI-assisted detection that goes beyond simple signature matching—think pattern recognition and contextual reasoning to uncover insecure coding practices, misconfigured permissions, or outdated components. • Coverage across three layers: the repository itself (static code analysis), live or staged endpoints (API interrogation), and infrastructure-as-code / cloud posture (config review). • A concise report, preferably in both JSON and human-readable HTML/Markdown, ranking each issue by severity and suggesting remediation steps. • Straightforward setup: environment requirements, installation commands, and an example project so I can verify results immediately. If you plan to tap into tools such as Python, Node, OpenAI functions, or established scanners like Bandit, Semgrep, or Trivy, just outline how they fit into the overall workflow—the end product must still feel like one cohesive harness rather than a loose bundle of scripts. Unit tests and clear documentation will be part of the hand-off. Once delivered, I will run the harness against a sample repository; acceptance is based on its ability to detect deliberately seeded flaws across code, API definitions, and Terraform-style cloud configs without producing excessive false positives. Let me know your approach, the high-level architecture you envision, and any assumptions you’ll need from my side before we get started.