Symfony 安全审计 是 AI Skill Hub 本期精选Agent工作流之一。综合评分 8.0 分,整体质量较高。我们强烈推荐将其纳入你的 AI 工具库,帮助提升工作效率。
Symfony 安全审计 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
Symfony 安全审计 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 克隆仓库 git clone https://github.com/vinceAmstoutz/symfony-security-auditor cd symfony-security-auditor # 查看安装说明 cat README.md # 按 README 完成环境依赖安装后即可使用
# 查看帮助 symfony-security-auditor --help # 基本运行 symfony-security-auditor [options] <input> # 详细使用说明请查阅文档 # https://github.com/vinceAmstoutz/symfony-security-auditor
# symfony-security-auditor 配置说明 # 查看配置选项 symfony-security-auditor --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export SYMFONY_SECURITY_AUDITOR_CONFIG="/path/to/config.yml"
AI-powered, multi-agent security auditor for Symfony applications. An adversarial Attacker ⚔ Reviewer loop catches the application-level flaws SAST tools miss. Provider-agnostic via symfony/ai.

[!NOTE] main holds exactly the latest release, so everything documented here is in the version you install. Development happens on version branches.
- Multi-agent loop — adversarial Attacker + skeptical Reviewer cut false positives across up to 3 iterations, with confirmed findings fed back so later iterations generalize patterns instead of re-finding the same bugs, and the Reviewer remembering its own rejections across runs. - 49 vulnerability types covering OWASP-aligned categories: Injection, Broken Access Control, Logic Flaws, Symfony-specific, Data Exposure, Cryptographic — including the modern Symfony 7.x/8.x surface (Authenticators, Messenger handlers, Webhooks, Serializer denormalizers, Schedules, RateLimiter, Mailer, cache poisoning). - Symfony-aware — understands Controllers, Voters, Forms, Firewalls, Routes, #[IsGranted], denyAccessUnlessGranted, #[MapRequestPayload], Twig/Live Components, and surfaces controllers without proper access checks. - Feature-based chunking — groups a controller with its entity, repository, form, voter, and templates so the Attacker can follow data flow across files. - Deterministic pre-scan — a zero-token risk-marker pass flags concrete locations (unserialize, |raw, hardcoded secrets, unsafe Doctrine, …) to focus the LLM; optional lean mode drops marker-free files to cut tokens. Results from other SAST tools can be imported as markers via SARIF. - Diff mode — audit:run --since=main audits only changed files for fast pull-request CI. - Cross-file investigation tools — Attacker (and optionally Reviewer) can read_file, grep, list_files, and lookup_advisory (zero-config live CVE lookups via composer audit, backed by Packagist + GitHub Security Advisories). - One-knob profiles — fast, balanced, and thorough preset the cost/speed/depth levers in a single line; any explicit key still wins. - Tunable for speed & cost — split-model (powerful Attacker + cheap Reviewer, ~20× cheaper), concurrent Attacker and Reviewer calls (attacker_max_concurrent / reviewer_max_concurrent), Anthropic prompt caching on by default (~90% input-token discount), content-hash caching that skips identical chunks, cheap→expensive escalation, and code slicing. - Secret-safe by default — credential-shaped strings are scrubbed from file content before it reaches the LLM, and privacy.offline_only refuses every network call the auditor owns (see Security by design). - Rate-limit aware — reactive retry with Retry-After-aware exponential backoff plus an optional proactive token-bucket limiter keep you inside provider quotas (see Cost & Performance). - Actionable findings — optionally attach a copy-pasteable reproduction (curl/console/payload) and a suggested patch to every high-severity finding; each one also carries a heuristic CVSS v4.0 estimate. - Nine output formats — console, executive (stakeholder summary: risk level, business impact, severity/type/hotspot distributions, no per-finding detail), json, sarif (GitHub Code Scanning / GitLab Security Dashboard), html (self-contained, shareable), markdown (PR-friendly), junit (CI test-report panels), github (inline PR annotations, no SARIF upload step), and github-comment (PR comment headlined by the grade and score, self-updating on rerun). Baseline suppression: --generate-baseline accepts known findings, --baseline drops them from the report and exit code so only new findings fail CI; --min-score gates on the normalized score independently of --fail-on. - Findings over time — audit:diff compares two JSON reports by finding fingerprint, audit:trend tracks counts across a series of them. - CI-ready — a reusable GitHub Action (uses: vinceamstoutz/symfony-security-auditor@1.20.1) plus GitLab CI templates, with SARIF upload to Code Scanning and an optional shields.io badge tracking the report's letter grade. See CI Integration. - Extensible — strict DDD layering and a sole LLMClientInterface seam let you plug in custom providers, agents, stages, advisory feeds, or report formats; project-specific attacker skills need only configuration, no PHP. - Bundle or standalone — install as a Symfony bundle, or run it like PHPStan/Psalm from a single self-contained binary configured once at the user level to audit any project with zero footprint, kept current with self-update and preflighted with doctor (see Standalone tool).
The auditor ships two maintained ways to run it — pick the one that fits:
- Standalone CLI (recommended) — one download, configured once, audits any project with zero footprint in it (like PHPStan or Psalm). Best for most users, and for auditing a project you don't want to add a dependency to. - Symfony bundle — wired into a Symfony app via Flex. Pick this to extend the auditor (custom services, decorated ports) or to pin it in the app's dev dependencies.
[!TIP] Both expose the same audit command, options, and output formats — see the CLI reference.
One command — Linux, macOS, and Windows (under WSL):
curl -fsSL https://raw.githubusercontent.com/vinceAmstoutz/symfony-security-auditor/main/install.sh | sh
install.sh detects your OS and CPU architecture, downloads the matching binary, and verifies its SHA-256 checksum before installing — anywhere you have a POSIX shell.
Native Windows (PowerShell) — when you are not using WSL; Git Bash / MSYS / Cygwin users need this installer too (install.sh detects those shells and points here):
irm https://raw.githubusercontent.com/vinceAmstoutz/symfony-security-auditor/main/install.ps1 | iex
[!TIP] One command, installed and configured. SetSSA_INIT=1and the installer runs the guidedinitfor you right after downloading — so you skip step 2. It prompts for your provider when a terminal is attached, and falls back to the Anthropic defaults non-interactively in a pipe or CI.initfetches the provider bridge withcomposer, so composer must be available for this combined step.> curl -fsSL https://raw.githubusercontent.com/vinceAmstoutz/symfony-security-auditor/main/install.sh | SSA_INIT=1 sh >
Or download the binary for your platform straight from the latest release:
| Platform | Asset |
|---|---|
| Linux x86-64 | symfony-security-auditor-linux-x86_64 |
| Linux arm64 | symfony-security-auditor-linux-aarch64 |
| macOS Intel | symfony-security-auditor-macos-x86_64 |
| macOS Apple Silicon | symfony-security-auditor-macos-arm64 |
| Windows x86-64 | symfony-security-auditor-windows-x86_64.exe |
Every binary ships with a .sha256 checksum, and the install scripts abort rather than install a binary they cannot verify. To check a manual download yourself:
sha256sum -c symfony-security-auditor-linux-x86_64.sha256
Installing the bundle requires PHP 8.3+ and Symfony 7.4+ in the host application (see composer.json) — the standalone binary has no such requirement, since it bundles its own runtime.
composer require --dev vinceamstoutz/symfony-security-auditor
The official Flex recipe registers the bundle (dev/test) and drops a pre-configured config/packages/symfony_security_auditor.yaml.
Not using Flex? See Manual setup.
```bash
symfony-security-auditor init
Writes the config file (~/.config/symfony-security-auditor/config.yaml on Linux/macOS, %APPDATA%\symfony-security-auditor\config.yaml on Windows) and downloads the provider bridge you pick. init fetches that bridge with composer, so composer must be available for this one-time setup step; running audits afterward needs only the binary. The file is rootless (the same keys as the bundle, without the symfony_security_auditor: wrapper) plus a platform: block handed verbatim to symfony/ai. See configuration for the format and provider switching.
export ANTHROPIC_API_KEY=sk-… symfony-security-auditor audit /path/to/your/symfony/project ```
audit is an alias for audit:run; every option documented in the CLI reference (--format, --output, --dry-run, --since, --fail-on, …) works identically.
```yaml
ai: platform: anthropic: api_key: '%env(ANTHROPIC_API_KEY)%' ```
The Flex recipe already created this file — pick your model:
```yaml
symfony_security_auditor: model: 'claude-opus-5'
Optionally pick a one-knob preset — `fast`, `balanced` (default), or `thorough`:
yaml
symfony_security_auditor: profile: 'fast' ```
A profile only fills the keys you leave unset — any explicitly configured key always wins. See Cost & Performance for exactly what each profile sets.
How much does an audit cost? Depends on project size and model. A medium Symfony app (~150 files) on Claude Opus + Haiku split-model with prompt caching enabled costs roughly $0.50 per nightly run. See CI → Managing LLM Costs.
Does it send my code to the cloud? Only to the LLM provider you configure, and credential-shaped strings are scrubbed first (see Security by design). For zero-cloud operation, use the Ollama local platform.
Full FAQ — privacy, false positives, model picks, comparisons: docs/faq.md.
高质量的自动化安全审计工具
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ MIT 协议 — 最宽松的开源协议之一,可自由商用、修改、分发,仅需保留版权声明。
经综合评估,Symfony 安全审计 在Agent工作流赛道中表现稳健,质量优秀。如果你已有明确的使用需求,可以直接上手体验;如果还在评估阶段,建议对比同类工具后再做决策。
| 原始名称 | symfony-security-auditor |
| 原始描述 | 开源AI工作流:AI-powered multi-agent security auditor for Symfony applications — provider-agno。⭐58 · PHP |
| Topics | AI安全Symfony多代理 |
| GitHub | https://github.com/vinceAmstoutz/symfony-security-auditor |
| License | MIT |
| 语言 | PHP |
收录时间:2026-06-24 · 更新时间:2026-06-26 · License:MIT · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端