Diff Scanning With Aws Security Agent

作者 aws7bde20faede4無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

僅含說明Security
AI 產生的概覽

對自某個 git 參照以來變更的程式碼執行 AWS Security Agent 差異掃描,並上傳差異與工作區以供審查。

功能
此技能引導代理執行僅針對自選定 git 參照以來變更程式碼的提交前或 PR 前安全掃描。它會讀取本機設定、產生 git 差異、壓縮工作區、將兩者上傳至 S3、建立或重用 CodeReview、啟動差異程式碼審查工作、每兩分鐘輪詢一次,並將依嚴重程度分組的發現寫入 Markdown 報告。
適用情境
當使用者要求掃描變更、執行差異掃描、檢查變更中的安全性問題,或執行提交前或推送前安全檢查時使用。它適用於只掃描變更程式碼而非整個程式庫的情境。
執行需求
需要帶有 securityagent 服務的 AWS CLI、git、zip、openssl、md5sum,以及對 AWS S3 和 Security Agent API 的網路存取。需要 .security-agent/config.json 中既有的代理空間設定、IAM 服務角色和 S3 儲存貯體;不附帶指令碼,僅提供指示。

AWS Security Agent — Diff Scan

Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Track scans in .security-agent/scans.json.

Resolving the values you need

PlaceholderHow to resolve
<id> (agent space)config.agent_space_id
<region>config.region (default us-east-1)
<account>aws sts get-caller-identity --query Account --output text
<role-arn>arn:aws:iam::<account>:role/SecurityAgentScanRole
<bucket>security-agent-scans-<account>-<region>
<WORKSPACE_ID>printf '%s' "$(pwd)" | md5sum | cut -c1-12

Workflow

  1. Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.

  2. Ask what to scan against:

    • Uncommitted changes → BASE_REF=HEAD (default)
    • Branch vs main → BASE_REF=main
    • Custom ref → user provides
  3. Generate diff (fail fast if empty):

    bash
    cd <absolute-workspace-path>if [ "$BASE_REF" = "HEAD" ]; then  git diff HEAD > /tmp/diff.patchelse  git diff "$BASE_REF..HEAD" > /tmp/diff.patchfi[ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; }
  4. Zip the workspace (same exclusions as full scan, 2 GB limit):

    bash
    cd <absolute-workspace-path>zip -r /tmp/source.zip . \  -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \  -x "__pycache__/*" -x ".venv/*" -x "venv/*" \  -x "dist/*" -x "build/*" -x "target/*" \  -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \  -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
  5. Upload both source zip and diff patch:

    bash
    SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)"aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip --expected-bucket-owner <account>aws s3 cp /tmp/diff.patch s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patch --expected-bucket-owner <account>
  6. Get or create per-workspace CodeReview (same logic as full scan — lookup config.json → code_reviews[<abs_path>], create if absent):

    bash
    aws securityagent create-code-review --agent-space-id <id> --title <title> \  --service-role <role-arn> \  --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip}]
  7. Start the diff job:

    bash
    aws securityagent start-code-review-job --agent-space-id <id> --code-review-id <cr-id> \  --diff-source s3Uri=s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patch

    If ResourceNotFoundException: recreate CodeReview and retry.

  8. Capture codeReviewJobId. Persist to scans.json with scan_type: "DIFF" and base_ref.

  9. Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."

  10. Poll every 2 minutes:

    bash
    aws securityagent batch-get-code-review-jobs --agent-space-id <id> --code-review-job-ids <job_id>

    Only respond when status changes. On COMPLETED → fetch findings.

  11. Findings: same presentation as full scan — grouped by severity, report written to .security-agent/findings-{scan_id}.md.


Rules

  • Diff scans are standalone — no prior full scan needed
  • Poll every 2 minutes, not faster
  • Default to BASE_REF=HEAD if user doesn't specify
  • Title: diff-<git-branch>-<timestamp> (no spaces)
  • If diff is empty, tell user and stop — don't start a scan

來源與署名

來源:aws/agent-toolkit-for-aws位於plugins/aws-agents-for-devsecops/skills/diff-scanning-with-aws-security-agent提交7bde20f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架