AgentStack
SKILL verified Apache-2.0 Self-run

Diff Scanning With Aws Security Agent

skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent · by aws

Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-aws-agent-toolkit-for-aws-diff-scanning-with-aws-security-agent

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Diff Scanning With Aws Security Agent? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AWS Security Agent — Diff Scan

Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Track scans in .security-agent/scans.json.

Resolving the values you need

| Placeholder | How to resolve | |-------------|----------------| | ` (agent space) | config.agentspaceid | | | config.region (default us-east-1) | | | aws sts get-caller-identity --query Account --output text | | | arn:aws:iam:::role/SecurityAgentScanRole | | | security-agent-scans-- | | | printf '%s' "$(pwd)" \| md5sum \| cut -c1-12` |


Workflow

  1. Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
  1. Ask what to scan against:
  • Uncommitted changes → BASE_REF=HEAD (default)
  • Branch vs main → BASE_REF=main
  • Custom ref → user provides
  1. Generate diff (fail fast if empty):

``bash cd if [ "$BASE_REF" = "HEAD" ]; then git diff HEAD > /tmp/diff.patch else git diff "$BASE_REF..HEAD" > /tmp/diff.patch fi [ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; } ``

  1. Zip the workspace (same exclusions as full scan, 2 GB limit):

``bash cd zip -r /tmp/source.zip . \ -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \ -x "__pycache__/*" -x ".venv/*" -x "venv/*" \ -x "dist/*" -x "build/*" -x "target/*" \ -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \ -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc" ``

  1. Upload both source zip and diff patch:

``bash SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)" aws s3 cp /tmp/source.zip s3:///security-scans/source//source.zip aws s3 cp /tmp/diff.patch s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``

  1. Get or create per-workspace CodeReview (same logic as full scan — lookup config.json → code_reviews[], create if absent):

``bash aws securityagent create-code-review --agent-space-id --title \ --service-role \ --assets sourceCode=[{s3Location=s3:///security-scans/source//source.zip}] ``

  1. Start the diff job:

``bash aws securityagent start-code-review-job --agent-space-id --code-review-id \ --diff-source s3Uri=s3:///security-scans/diffs/${SCAN_ID}/diff.patch ``

If ResourceNotFoundException: recreate CodeReview and retry.

  1. Capture codeReviewJobId. Persist to scans.json with scan_type: "DIFF" and base_ref.
  1. Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
  1. Poll every 2 minutes:

``bash aws securityagent batch-get-code-review-jobs --agent-space-id --code-review-job-ids ``

Only respond when status changes. On COMPLETED → fetch findings.

  1. Findings: same presentation as full scan — grouped by severity, report written to .security-agent/findings-{scan_id}.md.

Rules

  • Diff scans are standalone — no prior full scan needed
  • Poll every 2 minutes, not faster
  • Default to BASE_REF=HEAD if user doesn't specify
  • Title: diff-- (no spaces)
  • If diff is empty, tell user and stop — don't start a scan

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.