Threat Modeling With Aws Security Agent

作者 aws7bde20faede4无许可证2.8K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.

仅含说明Security
AI 生成的概览

使用 AWS Security Agent 依据 STRIDE 对规格文档进行威胁建模审查。

功能
该技能引导智能体向 AWS Security Agent 提交威胁建模审查。它收集 requirements.md 和 design.md 规格文件,打包工作区,将源代码和规格上传至 S3,创建并启动威胁建模任务,然后轮询直至完成。随后获取生成的威胁,按严重程度展示 STRIDE 类别、影响、受影响资产和建议,并将完整报告写入 findings 的 Markdown 文件。
适用场景
当用户要求对规格或设计进行安全审查、运行威胁建模、检查设计是否引入安全风险,或执行 STRIDE 分析时使用。它面向 requirements.md 或 design.md 等规格文档。
运行要求
需要具备可调用 AWS Security Agent 和 S3 的凭证的 AWS CLI、在 .security-agent/config.json 中配置的现有 agent space(agent_space_id 和 region)、一个 IAM 服务角色以及一个 S3 存储桶。它使用 zip、md5sum、openssl 和 date 等 shell 工具,并需要访问 AWS 的网络。它不附带脚本,仅为指令。

AWS Security Agent — Threat Model Review

Analyze spec documents (requirements.md, design.md) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Resolving the values you need

PlaceholderHow to resolve
<id> (agent space)config.agent_space_id
<region>config.region (default us-east-1)
<account>aws sts get-caller-identity --query Account --output text
<role-arn>arn:aws:iam::<account>:role/SecurityAgentScanRole
<bucket>security-agent-scans-<account>-<region>

Workflow

  1. Pre-checks. Read config, verify agent space, resolve values.

  2. Collect spec files. Identify the requirements.md and/or design.md the user is working on. Use absolute paths. Ask if unclear which files to review.

  3. Zip the workspace (same exclusions as code scan):

    bash
    cd <absolute-workspace-path>zip -r /tmp/source.zip . \  -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \  -x "__pycache__/*" -x ".venv/*" -x "venv/*" \  -x "dist/*" -x "build/*" -x "target/*" \  -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \  -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
  4. Upload source zip:

    bash
    SCAN_ID="tm-$(date +%s)-$(openssl rand -hex 3)"WORKSPACE_ID=$(printf '%s' "$(pwd)" | md5sum | cut -c1-12)aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip --expected-bucket-owner <account>
  5. Upload spec files:

    bash
    aws s3 cp /path/to/requirements.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/requirements.md --expected-bucket-owner <account>aws s3 cp /path/to/design.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/design.md --expected-bucket-owner <account>
  6. Create threat model:

    bash
    aws securityagent create-threat-model --agent-space-id <id> --title <title> \  --service-role <role-arn> \  --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip}] \  --scope-docs '[{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/requirements.md"},{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/design.md"}]'

    Capture threatModelId.

  7. Start threat model job:

    bash
    aws securityagent start-threat-model-job --agent-space-id <id> --threat-model-id <tm-id>

    Capture threatJobId.

  8. Persist to scans.json with scan_type: "THREAT_MODEL".

  9. Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."

  10. Poll every 2 minutes:

    bash
    aws securityagent batch-get-threat-model-jobs --agent-space-id <id> --threat-model-job-ids <tj-id>

    Only respond when status changes.

  11. On COMPLETED → fetch threats:

    bash
    aws securityagent list-threats --agent-space-id <id> --threat-job-id <tj-id>

    If nextToken, paginate with --next-token.

Findings presentation

Each threat includes: statement, severity, stride category, threatImpact, recommendation, impactedAssets.

🟣 CRITICAL: {statement}   STRIDE: {stride}   Impact: {threatImpact}   Assets: {impactedAssets}   Recommendation: {recommendation}
🔴 HIGH: {statement}   ...

Write full report to .security-agent/findings-{scan_id}.md. Call out any threat that represents a regression from the prior design.


Rules

  • Threat model reviews are standalone — no prior scan needed
  • Poll every 2 minutes, not faster
  • At least one spec file is required
  • Use absolute paths for workspace and spec files
  • Title: threat-model-<feature-name> (no spaces)

来源与署名

来源:aws/agent-toolkit-for-aws位于plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent提交7bde20f

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架