Threat Modeling With Aws Security Agent

作者 aws7bde20faede4無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.

僅含說明Security
AI 產生的概覽

使用 AWS Security Agent 依 STRIDE 對規格文件進行威脅建模審查。

功能
此技能引導代理向 AWS Security Agent 提交威脅建模審查。它會收集 requirements.md 與 design.md 規格檔案、壓縮工作區、將原始碼與規格上傳至 S3、建立並啟動威脅建模工作,然後輪詢直到完成。接著它會取得產生的威脅,依嚴重程度呈現 STRIDE 類別、影響、受影響資產與建議,並將完整報告寫入 findings 的 Markdown 檔案。
適用情境
當使用者要求對規格或設計進行安全審查、執行威脅建模、檢查設計是否引入安全風險,或進行 STRIDE 分析時使用。它適用於 requirements.md 或 design.md 等規格文件。
執行需求
需要具備可呼叫 AWS Security Agent 與 S3 之憑證的 AWS CLI、在 .security-agent/config.json 中設定的現有 agent space(agent_space_id 與 region)、一個 IAM 服務角色,以及一個 S3 儲存貯體。它使用 zip、md5sum、openssl 與 date 等 shell 工具,並需要存取 AWS 的網路。它不隨附指令碼,僅為指示。

AWS Security Agent — Threat Model Review

Analyze spec documents (requirements.md, design.md) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Resolving the values you need

PlaceholderHow to resolve
<id> (agent space)config.agent_space_id
<region>config.region (default us-east-1)
<account>aws sts get-caller-identity --query Account --output text
<role-arn>arn:aws:iam::<account>:role/SecurityAgentScanRole
<bucket>security-agent-scans-<account>-<region>

Workflow

  1. Pre-checks. Read config, verify agent space, resolve values.

  2. Collect spec files. Identify the requirements.md and/or design.md the user is working on. Use absolute paths. Ask if unclear which files to review.

  3. Zip the workspace (same exclusions as code scan):

    bash
    cd <absolute-workspace-path>zip -r /tmp/source.zip . \  -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \  -x "__pycache__/*" -x ".venv/*" -x "venv/*" \  -x "dist/*" -x "build/*" -x "target/*" \  -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \  -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
  4. Upload source zip:

    bash
    SCAN_ID="tm-$(date +%s)-$(openssl rand -hex 3)"WORKSPACE_ID=$(printf '%s' "$(pwd)" | md5sum | cut -c1-12)aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip --expected-bucket-owner <account>
  5. Upload spec files:

    bash
    aws s3 cp /path/to/requirements.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/requirements.md --expected-bucket-owner <account>aws s3 cp /path/to/design.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/design.md --expected-bucket-owner <account>
  6. Create threat model:

    bash
    aws securityagent create-threat-model --agent-space-id <id> --title <title> \  --service-role <role-arn> \  --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip}] \  --scope-docs '[{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/requirements.md"},{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/design.md"}]'

    Capture threatModelId.

  7. Start threat model job:

    bash
    aws securityagent start-threat-model-job --agent-space-id <id> --threat-model-id <tm-id>

    Capture threatJobId.

  8. Persist to scans.json with scan_type: "THREAT_MODEL".

  9. Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."

  10. Poll every 2 minutes:

    bash
    aws securityagent batch-get-threat-model-jobs --agent-space-id <id> --threat-model-job-ids <tj-id>

    Only respond when status changes.

  11. On COMPLETED → fetch threats:

    bash
    aws securityagent list-threats --agent-space-id <id> --threat-job-id <tj-id>

    If nextToken, paginate with --next-token.

Findings presentation

Each threat includes: statement, severity, stride category, threatImpact, recommendation, impactedAssets.

🟣 CRITICAL: {statement}   STRIDE: {stride}   Impact: {threatImpact}   Assets: {impactedAssets}   Recommendation: {recommendation}
🔴 HIGH: {statement}   ...

Write full report to .security-agent/findings-{scan_id}.md. Call out any threat that represents a regression from the prior design.


Rules

  • Threat model reviews are standalone — no prior scan needed
  • Poll every 2 minutes, not faster
  • At least one spec file is required
  • Use absolute paths for workspace and spec files
  • Title: threat-model-<feature-name> (no spaces)

來源與署名

來源:aws/agent-toolkit-for-aws位於plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent提交7bde20f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架