AWS Security Agent — Threat Model Review
Analyze spec documents (requirements.md, design.md) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.
Local state
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Resolving the values you need
Workflow
-
Pre-checks. Read config, verify agent space, resolve values.
-
Collect spec files. Identify the
requirements.mdand/ordesign.mdthe user is working on. Use absolute paths. Ask if unclear which files to review. -
Zip the workspace (same exclusions as code scan):
-
Upload source zip:
-
Upload spec files:
-
Create threat model:
Capture
threatModelId. -
Start threat model job:
Capture
threatJobId. -
Persist to
scans.jsonwithscan_type: "THREAT_MODEL". -
Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."
-
Poll every 2 minutes:
Only respond when status changes.
-
On COMPLETED → fetch threats:
If
nextToken, paginate with--next-token.
Findings presentation
Each threat includes: statement, severity, stride category, threatImpact, recommendation, impactedAssets.
Write full report to .security-agent/findings-{scan_id}.md. Call out any threat that represents a regression from the prior design.
Rules
- Threat model reviews are standalone — no prior scan needed
- Poll every 2 minutes, not faster
- At least one spec file is required
- Use absolute paths for workspace and spec files
- Title:
threat-model-<feature-name>(no spaces)

