AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Diff Scanning With Aws Security Agent

skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent · by aws

Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

— No reviews yet
0 installs
45 views
0.0% view→install

Install

$ agentstack add skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Diff Scanning With Aws Security Agent? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AWS Security Agent — Diff Scan

Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Track scans in .security-agent/scans.json.

Resolving the values you need

| Placeholder | How to resolve | |-------------|----------------| | ` (agent space) | config.agentspaceid | | | config.region (default us-east-1) | | | aws sts get-caller-identity --query Account --output text | | | arn:aws:iam:::role/SecurityAgentScanRole | | | security-agent-scans-- | | | printf '%s' "$(pwd)" \| md5sum \| cut -c1-12` |


Workflow

  1. Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
  1. Ask what to scan against:
  • Uncommitted changes → BASE_REF=HEAD (default)
  • Branch vs main → BASE_REF=main
  • Custom ref → user provides
  1. Generate diff (fail fast if empty):

``bash cd if [ "$BASE_REF" = "HEAD" ]; then git diff HEAD > /tmp/diff.patch else git diff "$BASE_REF..HEAD" > /tmp/diff.patch fi [ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; } ``

  1. Zip the workspace (same exclusions as full scan, 2 GB limit):

``bash cd zip -r /tmp/source.zip . \ -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \ -x "__pycache__/*" -x ".venv/*" -x "venv/*" \ -x "dist/*" -x "build/*" -x "target/*" \ -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \ -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc" ``

  1. Upload both source zip and diff patch:

``bash SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)" aws s3 cp /tmp/source.zip s3:///security-scans/source//source.zip aws s3 cp /tmp/diff.patch s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``

  1. Get or create per-workspace CodeReview (same logic as full scan — lookup config.json → code_reviews[], create if absent):

``bash aws securityagent create-code-review --agent-space-id --title \ --service-role \ --assets sourceCode=[{s3Location=s3:///security-scans/source//source.zip}] ``

  1. Start the diff job:

``bash aws securityagent start-code-review-job --agent-space-id --code-review-id \ --diff-source s3Uri=s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``

If ResourceNotFoundException: recreate CodeReview and retry.

  1. Capture codeReviewJobId. Persist to scans.json with scan_type: "DIFF" and base_ref.
  1. Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
  1. Poll every 2 minutes:

``bash aws securityagent batch-get-code-review-jobs --agent-space-id --code-review-job-ids ``

Only respond when status changes. On COMPLETED → fetch findings.

  1. Findings: same presentation as full scan — grouped by severity, report written to .security-agent/findings-{scan_id}.md.

Rules

  • Diff scans are standalone — no prior full scan needed
  • Poll every 2 minutes, not faster
  • Default to BASE_REF=HEAD if user doesn't specify
  • Title: diff-- (no spaces)
  • If diff is empty, tell user and stop — don't start a scan

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.