# Threat Modeling With Aws Security Agent

> Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.

- **Type:** Skill
- **Install:** `agentstack add skill-aws-agent-toolkit-for-aws-threat-modeling-with-aws-security-agent`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [aws](https://agentstack.voostack.com/s/aws)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [aws](https://github.com/aws)
- **Source:** https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent

## Install

```sh
agentstack add skill-aws-agent-toolkit-for-aws-threat-modeling-with-aws-security-agent
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# AWS Security Agent — Threat Model Review

Analyze spec documents (`requirements.md`, `design.md`) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.

## Local state

Read `.security-agent/config.json` for `agent_space_id` and `region`. If missing, run the `setup-security-agent` workflow inline first.

### Resolving the values you need

| Placeholder | How to resolve |
|-------------|----------------|
| `` (agent space) | `config.agent_space_id` |
| `` | `config.region` (default `us-east-1`) |
| `` | `aws sts get-caller-identity --query Account --output text` |
| `` | `arn:aws:iam:::role/SecurityAgentScanRole` |
| `` | `security-agent-scans--` |

---

## Workflow

1. **Pre-checks.** Read config, verify agent space, resolve values.

2. **Collect spec files.** Identify the `requirements.md` and/or `design.md` the user is working on. Use absolute paths. Ask if unclear which files to review.

3. **Zip the workspace** (same exclusions as code scan):

   ```bash
   cd 
   zip -r /tmp/source.zip . \
     -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \
     -x "__pycache__/*" -x ".venv/*" -x "venv/*" \
     -x "dist/*" -x "build/*" -x "target/*" \
     -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \
     -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
   ```

4. **Upload source zip:**

   ```bash
   SCAN_ID="tm-$(date +%s)-$(openssl rand -hex 3)"
   WORKSPACE_ID=$(printf '%s' "$(pwd)" | md5sum | cut -c1-12)
   aws s3 cp /tmp/source.zip s3:///security-scans/source/${WORKSPACE_ID}/source.zip
   ```

5. **Upload spec files:**

   ```bash
   aws s3 cp /path/to/requirements.md s3:///security-scans/threat-models/${SCAN_ID}/specs/requirements.md
   aws s3 cp /path/to/design.md s3:///security-scans/threat-models/${SCAN_ID}/specs/design.md
   ```

6. **Create threat model:**

   ```bash
   aws securityagent create-threat-model --agent-space-id  --title  \
     --service-role  \
     --assets sourceCode=[{s3Location=s3:///security-scans/source/${WORKSPACE_ID}/source.zip}] \
     --scope-docs '[{"s3Location":"s3:///security-scans/threat-models/'${SCAN_ID}'/specs/requirements.md"},{"s3Location":"s3:///security-scans/threat-models/'${SCAN_ID}'/specs/design.md"}]'
   ```

   Capture `threatModelId`.

7. **Start threat model job:**

   ```bash
   aws securityagent start-threat-model-job --agent-space-id  --threat-model-id 
   ```

   Capture `threatJobId`.

8. Persist to `scans.json` with `scan_type: "THREAT_MODEL"`.

9. Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."

10. **Poll** every 2 minutes:

    ```bash
    aws securityagent batch-get-threat-model-jobs --agent-space-id  --threat-model-job-ids 
    ```

    Only respond when status changes.

11. **On COMPLETED** → fetch threats:

    ```bash
    aws securityagent list-threats --agent-space-id  --threat-job-id 
    ```

    If `nextToken`, paginate with `--next-token`.

## Findings presentation

Each threat includes: `statement`, `severity`, `stride` category, `threatImpact`, `recommendation`, `impactedAssets`.

```
🟣 CRITICAL: {statement}
   STRIDE: {stride}
   Impact: {threatImpact}
   Assets: {impactedAssets}
   Recommendation: {recommendation}

🔴 HIGH: {statement}
   ...
```

Write full report to `.security-agent/findings-{scan_id}.md`. Call out any threat that represents a regression from the prior design.

---

## Rules

- Threat model reviews are standalone — no prior scan needed
- Poll every 2 minutes, not faster
- At least one spec file is required
- Use absolute paths for workspace and spec files
- Title: `threat-model-` (no spaces)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [aws](https://github.com/aws)
- **Source:** [aws/agent-toolkit-for-aws](https://github.com/aws/agent-toolkit-for-aws)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-aws-agent-toolkit-for-aws-threat-modeling-with-aws-security-agent
- Seller: https://agentstack.voostack.com/s/aws
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
