diff-scanning-with-aws-security-agent
aws/agent-toolkit-for-aws
Scan only changed code since a git ref for fast, focused security findings.
What is diff-scanning-with-aws-security-agent?
Run AWS Security Agent diff scans on only the code that changed since a specified git reference, without needing a prior full scan. Use this for pre-commit, pre-push, or pre-PR security checks to get faster results focused on your changes.
- Generates a diff patch between a base git ref (default HEAD) and current changes
- Uploads workspace source and diff to S3 for scanning
- Creates or reuses a per-workspace CodeReview in AWS Security Agent
- Starts a diff-focused scan job and polls for completion every 2 minutes
- Presents findings grouped by severity and saves report to .security-agent/findings-{scan_id}.md
- Excludes common build/cache directories (.git, node_modules, .venv, dist, etc.) to stay under 2 GB limit
How to install diff-scanning-with-aws-security-agent
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill diff-scanning-with-aws-security-agent- AWS Security Agent configured with .security-agent/config.json (agent_space_id and region)
- AWS credentials configured with permissions to call securityagent and S3 APIs
- Git repository with at least one commit
- Workspace under 2 GB after excluding standard build/cache directories
How to use diff-scanning-with-aws-security-agent
- 1.Ensure AWS Security Agent is set up by running setup-security-agent if .security-agent/config.json is missing
- 2.Specify the base git reference to compare against (default is HEAD for uncommitted changes; use 'main' for branch comparisons or provide a custom ref)
- 3.The skill generates a diff patch and uploads both source code and diff to S3
- 4.A CodeReview is created or reused for your workspace, and a diff scan job starts
- 5.Monitor progress as the skill polls every 2 minutes until the scan completes
- 6.Review findings grouped by severity in the console output and saved report
Use cases
- Scan uncommitted changes before committing to catch security issues early
- Compare a feature branch against main to review only new code for vulnerabilities
- Run a quick security check before pushing to verify no sensitive data or misconfigurations were introduced
- Validate pull request changes for security compliance before merging
- Integrate into CI/CD pre-commit hooks for automated security gates
- Developers integrating security scanning into local workflows
- DevOps engineers setting up pre-commit or pre-push security checks
- Security teams reviewing pull requests for compliance
- Teams using AWS Security Agent for centralized code scanning
diff-scanning-with-aws-security-agent FAQ
No. Diff scans are standalone and work without any prior full scan.
HEAD, which scans uncommitted changes in your working directory.
Every 2 minutes. You can say 'stop polling' to opt out of automatic checks.
.git, .security-agent, node_modules, __pycache__, .venv, venv, dist, build, target, .mypy_cache, .pytest_cache, .tox, .next, cdk.out, .DS_Store, and *.pyc files.
The skill detects an empty diff and stops without starting a scan, informing you there are no changes versus the base reference.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: diff-scanning-with-aws-security-agent description: Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.
AWS Security Agent — Diff Scan
Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.
Local state
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Track scans in .security-agent/scans.json.
Resolving the values you need
| Placeholder | How to resolve |
|---|---|
<id> (agent space) | config.agent_space_id |
<region> | config.region (default us-east-1) |
<account> | aws sts get-caller-identity --query Account --output text |
<role-arn> | arn:aws:iam::<account>:role/SecurityAgentScanRole |
<bucket> | security-agent-scans-<account>-<region> |
<WORKSPACE_ID> | printf '%s' "$(pwd)" | md5sum | cut -c1-12 |
Workflow
-
Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
-
Ask what to scan against:
- Uncommitted changes →
BASE_REF=HEAD(default) - Branch vs main →
BASE_REF=main - Custom ref → user provides
- Uncommitted changes →
-
Generate diff (fail fast if empty):
cd <absolute-workspace-path> if [ "$BASE_REF" = "HEAD" ]; then git diff HEAD > /tmp/diff.patch else git diff "$BASE_REF..HEAD" > /tmp/diff.patch fi [ -s /tmp/diff.patch ] || { echo "No changes vs $BASE_REF"; exit 1; } -
Zip the workspace (same exclusions as full scan, 2 GB limit):
cd <absolute-workspace-path> zip -r /tmp/source.zip . \ -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \ -x "__pycache__/*" -x ".venv/*" -x "venv/*" \ -x "dist/*" -x "build/*" -x "target/*" \ -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \ -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc" -
Upload both source zip and diff patch:
SCAN_ID="diff-$(date +%s)-$(openssl rand -hex 3)" aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip --expected-bucket-owner <account> aws s3 cp /tmp/diff.patch s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patch --expected-bucket-owner <account> -
Get or create per-workspace CodeReview (same logic as full scan — lookup
config.json → code_reviews[<abs_path>], create if absent):aws securityagent create-code-review --agent-space-id <id> --title <title> \ --service-role <role-arn> \ --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/<WORKSPACE_ID>/source.zip}] -
Start the diff job:
aws securityagent start-code-review-job --agent-space-id <id> --code-review-id <cr-id> \ --diff-source s3Uri=s3://<bucket>/security-scans/diffs/${SCAN_ID}/diff.patchIf
ResourceNotFoundException: recreate CodeReview and retry. -
Capture
codeReviewJobId. Persist toscans.jsonwithscan_type: "DIFF"andbase_ref. -
Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
-
Poll every 2 minutes:
aws securityagent batch-get-code-review-jobs --agent-space-id <id> --code-review-job-ids <job_id>Only respond when status changes. On COMPLETED → fetch findings.
-
Findings: same presentation as full scan — grouped by severity, report written to
.security-agent/findings-{scan_id}.md.
Rules
- Diff scans are standalone — no prior full scan needed
- Poll every 2 minutes, not faster
- Default to
BASE_REF=HEADif user doesn't specify - Title:
diff-<git-branch>-<timestamp>(no spaces) - If diff is empty, tell user and stop — don't start a scan
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

directconnect
Configure AWS Direct Connect for private, consistent network links between data centers and AWS.

dms-schema-conversion
Migrate database schemas between heterogeneous engines using AWS DMS Schema Conversion

enabling-lambda-vpc-internet-access
Enable internet access for Lambda functions in VPC subnets via NAT Gateway infrastructure

exploring-data-catalog
Inventory and audit AWS Glue Data Catalog, S3 Tables, Redshift-federated, and Iceberg catalogs.

exporting-rds-to-s3
Export RDS/Aurora snapshots to S3 in Parquet format for analytics and migration.

finding-data-lake-assets
Resolve data lake asset references across Glue, S3, and Redshift catalogs.