Install
$ agentstack add skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
AWS Security Agent — Diff Scan
Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.
Local state
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Track scans in .security-agent/scans.json.
Resolving the values you need
| Placeholder | How to resolve | |-------------|----------------| | ` (agent space) | config.agentspaceid | | | config.region (default us-east-1) | | | aws sts get-caller-identity --query Account --output text | | | arn:aws:iam:::role/SecurityAgentScanRole | | | security-agent-scans-- | | | printf '%s' "$(pwd)" \| md5sum \| cut -c1-12` |
Workflow
- Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
- Ask what to scan against:
- Uncommitted changes →
BASE_REF=HEAD(default) - Branch vs main →
BASE_REF=main - Custom ref → user provides
- Generate diff (fail fast if empty):
``bash cd if [ "$BASE_REF" = "HEAD" ]; then git diff HEAD > /tmp/diff.patch else git diff "$BASE_REF..HEAD" > /tmp/diff.patch fi [ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; } ``
- Zip the workspace (same exclusions as full scan, 2 GB limit):
``bash cd zip -r /tmp/source.zip . \ -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \ -x "__pycache__/*" -x ".venv/*" -x "venv/*" \ -x "dist/*" -x "build/*" -x "target/*" \ -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \ -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc" ``
- Upload both source zip and diff patch:
``bash SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)" aws s3 cp /tmp/source.zip s3:///security-scans/source//source.zip aws s3 cp /tmp/diff.patch s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``
- Get or create per-workspace CodeReview (same logic as full scan — lookup
config.json → code_reviews[], create if absent):
``bash aws securityagent create-code-review --agent-space-id --title \ --service-role \ --assets sourceCode=[{s3Location=s3:///security-scans/source//source.zip}] ``
- Start the diff job:
``bash aws securityagent start-code-review-job --agent-space-id --code-review-id \ --diff-source s3Uri=s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``
If ResourceNotFoundException: recreate CodeReview and retry.
- Capture
codeReviewJobId. Persist toscans.jsonwithscan_type: "DIFF"andbase_ref.
- Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
- Poll every 2 minutes:
``bash aws securityagent batch-get-code-review-jobs --agent-space-id --code-review-job-ids ``
Only respond when status changes. On COMPLETED → fetch findings.
- Findings: same presentation as full scan — grouped by severity, report written to
.security-agent/findings-{scan_id}.md.
Rules
- Diff scans are standalone — no prior full scan needed
- Poll every 2 minutes, not faster
- Default to
BASE_REF=HEADif user doesn't specify - Title:
diff--(no spaces) - If diff is empty, tell user and stop — don't start a scan
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: aws
- Source: aws/agent-toolkit-for-aws
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.