
Threat Modeling With Aws Security Agent
作者 aws7bde20faede4無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新
Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.
新增到 SourceWeft 工作區
- 在儀表板中開啟該技能,並將它新增到工作區。
- 為需要使用它的對話啟用該技能。
該技能僅含說明:不附帶任何可執行的腳本。
新增到 SourceWeft系統會先要求你登入,然後直接帶你回到這個技能。
讓你的代理程式來安裝
把這段提示詞貼上到 Claude Code、Codex、Cursor 或其他能執行命令的代理程式中,也可以貼上到 SourceWeft 對話裡。代理程式會閱讀這個技能的安裝說明,向你展示它的來源、授權條款和腳本情況,在你同意後用 SourceWeft CLI 安裝。
閱讀 https://sourceweft.com/skills/gh-aws-agent-toolkit-for-aws-threat-modeling-with-aws-security-agent/install.md 中的說明,按說明安裝這個技能。安裝前先告訴我它的來源、授權條款以及是否附帶腳本,等我確認。修改我電腦上的其他任何內容之前也要先問我。用命令列自行安裝
適用於 Claude Code、Codex、Cursor 及其他本機代理程式。SourceWeft CLI 會從原始碼儲存庫中取得此處掃描過的那次提交,並根據掃描時記錄的雜湊值逐一驗證每個檔案。只要有任何不一致,就不會寫入任何內容。
npx @sourceweft/cli skills install gh-aws-agent-toolkit-for-aws-threat-modeling-with-aws-security-agent新增 --agent claude-code、codex、cursor 或 universal 來選擇安裝給哪個代理程式(預設為 Claude Code)。
上游安裝器——未經 SourceWeft 驗證
開源的 skills 安裝器會取得同一個固定的提交,但不會根據 SourceWeft 記錄的雜湊值驗證檔案。
npx skills add https://github.com/aws/agent-toolkit-for-aws/tree/7bde20faede49dd5764c02b54f5e306849f7e3ca/plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent來源與署名
來源:aws/agent-toolkit-for-aws位於plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent提交7bde20f
授權條款: 無授權條款
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 aws/agent-toolkit-for-aws 的技能

Signing In To Aws
aws
引導開發者使用 aws login 指令取得短期 AWS CLI/SDK 憑證。

Aws Well Architected Review
aws
依據即時 AWS Well-Architected Framework 審查工作負載,評估每項最佳實務並產出有證據支撐的報告。

Aws Storage
aws
針對 AWS 物件、檔案與區塊儲存服務的選擇、比較與維運提供建議。

Aws Serverless
aws
將 AWS 無伺服器請求路由到運算形態以及負責該形態的專用技能。

Aws Security
aws
審查 AWS 安全服務設定,並彙總 GuardDuty、Inspector、Security Hub、Macie、Detective 與 Security Lake 的發現結果。

Aws Sdk Swift Usage
aws
使用 AWS SDK for Swift 撰寫 Swift 程式的參考模式。
更多Security技能

Dpop Adoption
指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Secops Triage
引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Secops Investigate
指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Secops Hunt
指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Secops Cases
透過 MCP 工具管理 Google Security Operations SOAR 案件的完整生命週期。

Iam Helper For Privileged Access Management
引導 Google Cloud Privileged Access Manager 的權限配置增刪改查、臨時存取申請與授權審批流程。