PluginBench
Skill
Official
Pass
Audit score 90

threat-modeling-with-aws-security-agent

aws/agent-toolkit-for-aws

Analyze design specs for security threats using AWS Security Agent STRIDE methodology.

What is threat-modeling-with-aws-security-agent?

Run an automated threat model review on your requirements.md and design.md files to identify security-posture changes and vulnerabilities. Use this when you need to assess a design for security risks, validate threat coverage, or perform STRIDE analysis before implementation.

  • Analyzes spec documents against source code using STRIDE threat-modeling methodology
  • Identifies security-posture changes and regressions from prior designs
  • Categorizes threats by severity (Critical, High, Medium, Low) and STRIDE category
  • Generates detailed findings reports with impact assessment and remediation recommendations
  • Polls AWS Security Agent job status automatically until completion
  • Supports both requirements.md and design.md files or either individually

How to install threat-modeling-with-aws-security-agent

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill threat-modeling-with-aws-security-agent
Prerequisites
  • AWS account with Security Agent enabled and configured
  • `.security-agent/config.json` with `agent_space_id` and `region` (or run setup-security-agent first)
  • IAM permissions to call `securityagent:*` and `s3:PutObject` on the scan bucket
  • At least one spec file (requirements.md or design.md) in the workspace
Claude Code
Cursor
Windsurf
Cline

How to use threat-modeling-with-aws-security-agent

  1. 1.Ensure your workspace has a requirements.md and/or design.md file describing the design or feature
  2. 2.Run the skill and specify which spec files to review (or let it auto-detect)
  3. 3.The skill zips your workspace, uploads it and the spec files to S3, and creates a threat model in AWS Security Agent
  4. 4.A threat model job starts automatically; the skill polls every 2 minutes for completion
  5. 5.Once complete, a detailed findings report is written to `.security-agent/findings-{scan_id}.md` with all threats, severity, STRIDE categories, and recommendations
  6. 6.Review the report and address any Critical or High severity threats before proceeding

Use cases

Good for
  • Review a new microservice architecture design for authentication and authorization gaps
  • Validate that a data-handling redesign doesn't introduce privacy or encryption risks
  • Assess security impact of migrating workloads to a new AWS service or region
  • Identify threat coverage gaps before submitting design for compliance review
  • Compare threat landscape between current and proposed system designs
Who it's for
  • Security architects and threat modelers
  • Software engineers designing new features or systems
  • DevSecOps and security teams conducting design reviews
  • Compliance and risk management roles
  • Teams preparing for security audits or certifications

threat-modeling-with-aws-security-agent FAQ

Do I need to run a code scan first?

No. Threat model reviews are standalone and do not require a prior security scan. The skill analyzes your spec documents and source code together.

How long does a threat model review take?

Runtime varies with workspace size. The skill polls every 2 minutes and will notify you when complete. You can say 'stop polling' to opt out of automatic polling.

What if I only have a design.md and no requirements.md?

At least one spec file is required. You can run the threat model with just design.md, or just requirements.md.

What do the STRIDE categories mean?

STRIDE is a threat-modeling framework: Spoofing (identity), Tampering (data integrity), Repudiation (accountability), Information Disclosure (confidentiality), Denial of Service (availability), and Elevation of Privilege (authorization).

How do I know if a threat is a regression?

The skill compares findings against prior designs and explicitly calls out any threat that represents a security regression in the report.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: threat-modeling-with-aws-security-agent description: Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.

AWS Security Agent — Threat Model Review

Analyze spec documents (requirements.md, design.md) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.

Local state

Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.

Resolving the values you need

PlaceholderHow to resolve
<id> (agent space)config.agent_space_id
<region>config.region (default us-east-1)
<account>aws sts get-caller-identity --query Account --output text
<role-arn>arn:aws:iam::<account>:role/SecurityAgentScanRole
<bucket>security-agent-scans-<account>-<region>

Workflow

  1. Pre-checks. Read config, verify agent space, resolve values.

  2. Collect spec files. Identify the requirements.md and/or design.md the user is working on. Use absolute paths. Ask if unclear which files to review.

  3. Zip the workspace (same exclusions as code scan):

    cd <absolute-workspace-path>
    zip -r /tmp/source.zip . \
      -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \
      -x "__pycache__/*" -x ".venv/*" -x "venv/*" \
      -x "dist/*" -x "build/*" -x "target/*" \
      -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \
      -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc"
    
  4. Upload source zip:

    SCAN_ID="tm-$(date +%s)-$(openssl rand -hex 3)"
    WORKSPACE_ID=$(printf '%s' "$(pwd)" | md5sum | cut -c1-12)
    aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip --expected-bucket-owner <account>
    
  5. Upload spec files:

    aws s3 cp /path/to/requirements.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/requirements.md --expected-bucket-owner <account>
    aws s3 cp /path/to/design.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/design.md --expected-bucket-owner <account>
    
  6. Create threat model:

    aws securityagent create-threat-model --agent-space-id <id> --title <title> \
      --service-role <role-arn> \
      --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip}] \
      --scope-docs '[{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/requirements.md"},{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/design.md"}]'
    

    Capture threatModelId.

  7. Start threat model job:

    aws securityagent start-threat-model-job --agent-space-id <id> --threat-model-id <tm-id>
    

    Capture threatJobId.

  8. Persist to scans.json with scan_type: "THREAT_MODEL".

  9. Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."

  10. Poll every 2 minutes:

    aws securityagent batch-get-threat-model-jobs --agent-space-id <id> --threat-model-job-ids <tj-id>
    

    Only respond when status changes.

  11. On COMPLETED → fetch threats:

    aws securityagent list-threats --agent-space-id <id> --threat-job-id <tj-id>
    

    If nextToken, paginate with --next-token.

Findings presentation

Each threat includes: statement, severity, stride category, threatImpact, recommendation, impactedAssets.

🟣 CRITICAL: {statement}
   STRIDE: {stride}
   Impact: {threatImpact}
   Assets: {impactedAssets}
   Recommendation: {recommendation}

🔴 HIGH: {statement}
   ...

Write full report to .security-agent/findings-{scan_id}.md. Call out any threat that represents a regression from the prior design.


Rules

  • Threat model reviews are standalone — no prior scan needed
  • Poll every 2 minutes, not faster
  • At least one spec file is required
  • Use absolute paths for workspace and spec files
  • Title: threat-model-<feature-name> (no spaces)