AWS Security Agent — Diff Scan
Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.
Local state
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Track scans in .security-agent/scans.json.
Resolving the values you need
Workflow
-
Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
-
Ask what to scan against:
- Uncommitted changes →
BASE_REF=HEAD(default) - Branch vs main →
BASE_REF=main - Custom ref → user provides
- Uncommitted changes →
-
Generate diff (fail fast if empty):
-
Zip the workspace (same exclusions as full scan, 2 GB limit):
-
Upload both source zip and diff patch:
-
Get or create per-workspace CodeReview (same logic as full scan — lookup
config.json → code_reviews[<abs_path>], create if absent): -
Start the diff job:
If
ResourceNotFoundException: recreate CodeReview and retry. -
Capture
codeReviewJobId. Persist toscans.jsonwithscan_type: "DIFF"andbase_ref. -
Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
-
Poll every 2 minutes:
Only respond when status changes. On COMPLETED → fetch findings.
-
Findings: same presentation as full scan — grouped by severity, report written to
.security-agent/findings-{scan_id}.md.
Rules
- Diff scans are standalone — no prior full scan needed
- Poll every 2 minutes, not faster
- Default to
BASE_REF=HEADif user doesn't specify - Title:
diff-<git-branch>-<timestamp>(no spaces) - If diff is empty, tell user and stop — don't start a scan
