PluginBench
Skill
Official
Pass
Audit score 90

diff-scanning-with-aws-security-agent

aws/agent-toolkit-for-aws

Scan only changed code since a git ref for fast, focused security findings.

What is diff-scanning-with-aws-security-agent?

Run AWS Security Agent diff scans on only the code that changed since a specified git reference, without needing a prior full scan. Use this for pre-commit, pre-push, or pre-PR security checks to get faster results focused on your changes.

  • Generates a diff patch between a base git ref (default HEAD) and current changes
  • Uploads workspace source and diff to S3 for scanning
  • Creates or reuses a per-workspace CodeReview in AWS Security Agent
  • Starts a diff-focused scan job and polls for completion every 2 minutes
  • Presents findings grouped by severity and saves report to .security-agent/findings-{scan_id}.md
  • Excludes common build/cache directories (.git, node_modules, .venv, dist, etc.) to stay under 2 GB limit

How to install diff-scanning-with-aws-security-agent

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill diff-scanning-with-aws-security-agent
Prerequisites
  • AWS Security Agent configured with .security-agent/config.json (agent_space_id and region)
  • AWS credentials configured with permissions to call securityagent and S3 APIs
  • Git repository with at least one commit
  • Workspace under 2 GB after excluding standard build/cache directories
Claude Code
Cursor
Windsurf
Cline

How to use diff-scanning-with-aws-security-agent

  1. 1.Ensure AWS Security Agent is set up by running setup-security-agent if .security-agent/config.json is missing
  2. 2.Specify the base git reference to compare against (default is HEAD for uncommitted changes; use 'main' for branch comparisons or provide a custom ref)
  3. 3.The skill generates a diff patch and uploads both source code and diff to S3
  4. 4.A CodeReview is created or reused for your workspace, and a diff scan job starts
  5. 5.Monitor progress as the skill polls every 2 minutes until the scan completes
  6. 6.Review findings grouped by severity in the console output and saved report

Use cases

Good for
  • Scan uncommitted changes before committing to catch security issues early
  • Compare a feature branch against main to review only new code for vulnerabilities
  • Run a quick security check before pushing to verify no sensitive data or misconfigurations were introduced
  • Validate pull request changes for security compliance before merging
  • Integrate into CI/CD pre-commit hooks for automated security gates
Who it's for
  • Developers integrating security scanning into local workflows
  • DevOps engineers setting up pre-commit or pre-push security checks
  • Security teams reviewing pull requests for compliance
  • Teams using AWS Security Agent for centralized code scanning

diff-scanning-with-aws-security-agent FAQ

Do I need to run a full scan first?

No. Diff scans are standalone and work without any prior full scan.

What's the default base reference if I don't specify one?

HEAD, which scans uncommitted changes in your working directory.

How often does the skill check for scan completion?

Every 2 minutes. You can say 'stop polling' to opt out of automatic checks.

What directories are excluded from the scan?

.git, .security-agent, node_modules, __pycache__, .venv, venv, dist, build, target, .mypy_cache, .pytest_cache, .tox, .next, cdk.out, .DS_Store, and *.pyc files.

What happens if there are no changes to scan?

The skill detects an empty diff and stops without starting a scan, informing you there are no changes versus the base reference.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: diff-scanning-with-aws-security-agent description: Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

AWS Security Agent — Diff Scan

Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Track scans in .security-agent/scans.json.

Resolving the values you need

PlaceholderHow to resolve
<id> (agent space)config.agent_space_id
<region>config.region (default us-east-1)
<account>aws sts get-caller-identity --query Account --output text
<role-arn>arn:aws:iam::<account>:role/SecurityAgentScanRole
<bucket>security-agent-scans-<account>-<region>
<WORKSPACE_ID>printf '%s' "$(pwd)" | md5sum | cut -c1-12

Workflow

  1. Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.

  2. Ask what to scan against:

    • Uncommitted changes → BASE_REF=HEAD (default)
    • Branch vs main → BASE_REF=main
    • Custom ref → user provides
  3. Generate diff (fail fast if empty):

    cd <absolute-workspace-path>
    if [ "$BASE_REF" = "HEAD" ]; then
      git diff HEAD > /tmp/diff.patch
    else
      git diff "$BASE_REF..HEAD" > /tmp/diff.patch
    fi
    [ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; }
    
  4. Zip the workspace (same exclusions as full scan, 2 GB limit):

    cd <absolute-workspace-path>
    zip -r /tmp/source.zip . \
      -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \
      -x "__pycache__/*" -x ".venv/*" -x "venv/*" \
      -x "dist/*" -x "build/*" -x "target/*" \
      -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \
      -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
    
  5. Upload both source zip and diff patch:

    SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)"
    aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip --expected-bucket-owner <account>
    aws s3 cp /tmp/diff.patch s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patch --expected-bucket-owner <account>
    
  6. Get or create per-workspace CodeReview (same logic as full scan — lookup config.json → code_reviews[<abs_path>], create if absent):

    aws securityagent create-code-review --agent-space-id <id> --title <title> \
      --service-role <role-arn> \
      --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip}]
    
  7. Start the diff job:

    aws securityagent start-code-review-job --agent-space-id <id> --code-review-id <cr-id> \
      --diff-source s3Uri=s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patch
    

    If ResourceNotFoundException: recreate CodeReview and retry.

  8. Capture codeReviewJobId. Persist to scans.json with scan_type: "DIFF" and base_ref.

  9. Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."

  10. Poll every 2 minutes:

    aws securityagent batch-get-code-review-jobs --agent-space-id <id> --code-review-job-ids <job_id>
    

    Only respond when status changes. On COMPLETED → fetch findings.

  11. Findings: same presentation as full scan — grouped by severity, report written to .security-agent/findings-{scan_id}.md.


Rules

  • Diff scans are standalone — no prior full scan needed
  • Poll every 2 minutes, not faster
  • Default to BASE_REF=HEAD if user doesn't specify
  • Title: diff-<git-branch>-<timestamp> (no spaces)
  • If diff is empty, tell user and stop — don't start a scan