AWS Security Agent — Code Scans
This skill handles full repository scans. Setup (agent space, role, bucket) is handled by the setup-security-agent skill — if .security-agent/config.json is missing, the scan workflow auto-runs setup inline first.
Action mapping
Rules for proactive suggestions
- Always ask before running — never auto-trigger scans
- Single-line suggestions, not multi-paragraph pitches
- If the user declines, do not bring it up again in the same session
Local state
Read .security-agent/config.json for agent_space_id and region. If config.json is missing, tell the user one line — "First scan in this workspace — running setup first." — and run the setup-security-agent workflow inline (steps from that skill's SKILL.md) before continuing. First-time scans should "just work."
Track scans in .security-agent/scans.json (keep last 50 entries). The per-workspace CodeReview ID is stored in config.json → code_reviews[<abs_path>] so subsequent scans reuse the same CodeReview.
Resolving the values you need
The CLI examples below use placeholders. Resolve them at the start of every scan:
These are derived rather than stored in config so they can never drift out of sync with reality.
Pre-scan checks
-
Read
config.json. If missing → run thesetup-security-agentworkflow inline first, then continue. -
Verify agent space still exists:
If response shows it doesn't exist, clear
agent_space_idfromconfig.jsonand runsetup-security-agentagain. -
Resolve account, role ARN, and bucket name from the table above.
-
Generate workspace ID:
Workflow: Full Scan (~45 min)
For scanning only changed code, use the diff-scanning-with-aws-security-agent skill instead. For threat modeling specs, use threat-modeling-with-aws-security-agent.
-
Run pre-scan checks above.
-
Zip the workspace. Exclude common build/cache directories. Honor
.gitignore. Bail if zip > 2 GB. -
Upload to the per-workspace stable key (overwrites any prior upload):
-
Get or create the per-workspace CodeReview. Look up
config.json → code_reviews[<abs_path>].-
If present, use that
code_review_id. -
If absent, create:
Capture
codeReviewIdand persist toconfig.json → code_reviews[<abs_path>]. -
Title default:
pre-cr-<git-branch>(usegit rev-parse --abbrev-ref HEAD). Replace any spaces with hyphens.
-
-
Start the job:
- If the response is
ResourceNotFoundException: the CodeReview was deleted externally. Recreate it (step 4) and retry.
- If the response is
-
Capture
codeReviewJobId. Generate a localscan_idlikescan-<8-hex>. Append toscans.json: -
Tell user: "Full scan started (scan_id: {id}). Takes ~45 minutes. I'll check every 5 minutes — say 'stop polling' to opt out."
-
Run the Polling Loop below with
sleep 300between checks.
Polling Loop
After starting a scan:
-
sleep 300(5 minutes). Do not poll faster than this. -
Call status:
-
Compare
statusto last seen status. Only respond to the user when status CHANGES (e.g.,IN_PROGRESS→COMPLETED) or on terminal state (COMPLETED,FAILED,STOPPED). -
Do not report "still in progress" multiple times — that's noise.
-
If user says "stop polling" or "check later" → stop the loop and tell them: "Say 'scan status' or 'show findings' anytime."
-
On
COMPLETED→ run the Findings workflow. -
On
FAILED→ fetch the job's error info (statusReasonif present), tell the user, write a brief failure note to.security-agent/findings-{scan_id}.md.
Workflow: Status check (ad-hoc)
User says "scan status" / "how's the scan":
- If user names a
scan_id, use it. Otherwise use the most recent entry inscans.json. - Call
batch-get-code-review-jobsonce. - Update
scans.jsonstatus field. - Report: status + elapsed time + current step (if any).
Workflow: Findings
After a scan completes (or on user request):
1. Fetch findings (paginate)
If nextToken is returned, call again with --next-token <token> until exhausted.
2. Enrich with full details
3. Filter (optional)
If the user asked for a minimum severity (e.g., "high and above"), filter to that level:
- Severity order: CRITICAL > HIGH > MEDIUM > LOW > INFORMATIONAL.
4. Concise summary in chat
Group by severity. File path + line for each:
5. Detailed report file
Write to .security-agent/findings-{scan_id}.md. Include EVERY field returned (findingId, name, description, riskLevel, riskType, confidence, status, codeLocations with filePath/lineStart/lineEnd, and remediationCode if present).
Tell user: "Full details written to .security-agent/findings-{scan_id}.md"
6. Follow-ups
Ask:
- "Would you like to focus on the critical/high findings first?"
- "Should I explain any of these in more detail?"
- "Want me to fix these issues?"
For fixes: read the finding's description and code location, then synthesize and apply the fix via the Edit tool.
Workflow: Stop a scan
User says "stop the scan":
Update scans.json status to STOPPED.
Workflow: List recent scans
User asks "show my recent scans" / "list scans":
Read .security-agent/scans.json. Show in a compact table:
Rules
- Always run pre-scan checks (config exists + agent space verified) before any scan
- Scan APIs return immediately — poll status every 5 minutes
- Use the most recent scan in
scans.jsonif the user doesn't name one - Title must not contain spaces — use hyphens. Default to git branch name.
- Don't dump raw JSON — format with severity icons + file locations
- On
ResourceNotFoundExceptionfromstart-code-review-job, recreate the CodeReview and retry once
Troubleshooting
- "Not configured" /
config.jsonmissing → runsetup-security-agentskill first AccessDeniedons3 cp→ bucket not registered on agent space, or trust policy wrong. Re-run setup.403/ExpectedBucketOwnermismatch ons3 cp→ the derived bucket is owned by a different account (bucket-squatting). The upload is rejected by design — do not retry without the guard. Re-runsetup-security-agent, which aborts on foreign-owned buckets.ResourceNotFoundExceptionon agent space → it was deleted. Re-run setup.- Scan stuck in PREFLIGHT for >10 min → backend issue, not client. Show
batch-get-code-review-jobsoutput and tell user to escalate. - Code too large (zip > 2 GB) → run on a subdirectory instead.

