threat-modeling-with-aws-security-agent
aws/agent-toolkit-for-aws
Analyze design specs for security threats using AWS Security Agent STRIDE methodology.
What is threat-modeling-with-aws-security-agent?
Run an automated threat model review on your requirements.md and design.md files to identify security-posture changes and vulnerabilities. Use this when you need to assess a design for security risks, validate threat coverage, or perform STRIDE analysis before implementation.
- Analyzes spec documents against source code using STRIDE threat-modeling methodology
- Identifies security-posture changes and regressions from prior designs
- Categorizes threats by severity (Critical, High, Medium, Low) and STRIDE category
- Generates detailed findings reports with impact assessment and remediation recommendations
- Polls AWS Security Agent job status automatically until completion
- Supports both requirements.md and design.md files or either individually
How to install threat-modeling-with-aws-security-agent
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill threat-modeling-with-aws-security-agent- AWS account with Security Agent enabled and configured
- `.security-agent/config.json` with `agent_space_id` and `region` (or run setup-security-agent first)
- IAM permissions to call `securityagent:*` and `s3:PutObject` on the scan bucket
- At least one spec file (requirements.md or design.md) in the workspace
How to use threat-modeling-with-aws-security-agent
- 1.Ensure your workspace has a requirements.md and/or design.md file describing the design or feature
- 2.Run the skill and specify which spec files to review (or let it auto-detect)
- 3.The skill zips your workspace, uploads it and the spec files to S3, and creates a threat model in AWS Security Agent
- 4.A threat model job starts automatically; the skill polls every 2 minutes for completion
- 5.Once complete, a detailed findings report is written to `.security-agent/findings-{scan_id}.md` with all threats, severity, STRIDE categories, and recommendations
- 6.Review the report and address any Critical or High severity threats before proceeding
Use cases
- Review a new microservice architecture design for authentication and authorization gaps
- Validate that a data-handling redesign doesn't introduce privacy or encryption risks
- Assess security impact of migrating workloads to a new AWS service or region
- Identify threat coverage gaps before submitting design for compliance review
- Compare threat landscape between current and proposed system designs
- Security architects and threat modelers
- Software engineers designing new features or systems
- DevSecOps and security teams conducting design reviews
- Compliance and risk management roles
- Teams preparing for security audits or certifications
threat-modeling-with-aws-security-agent FAQ
No. Threat model reviews are standalone and do not require a prior security scan. The skill analyzes your spec documents and source code together.
Runtime varies with workspace size. The skill polls every 2 minutes and will notify you when complete. You can say 'stop polling' to opt out of automatic polling.
At least one spec file is required. You can run the threat model with just design.md, or just requirements.md.
STRIDE is a threat-modeling framework: Spoofing (identity), Tampering (data integrity), Repudiation (accountability), Information Disclosure (confidentiality), Denial of Service (availability), and Elevation of Privilege (authorization).
The skill compares findings against prior designs and explicitly calls out any threat that represents a security regression in the report.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: threat-modeling-with-aws-security-agent description: Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.
AWS Security Agent — Threat Model Review
Analyze spec documents (requirements.md, design.md) against the source code to identify security-posture changes using STRIDE methodology. No prior scan needed.
Local state
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Resolving the values you need
| Placeholder | How to resolve |
|---|---|
<id> (agent space) | config.agent_space_id |
<region> | config.region (default us-east-1) |
<account> | aws sts get-caller-identity --query Account --output text |
<role-arn> | arn:aws:iam::<account>:role/SecurityAgentScanRole |
<bucket> | security-agent-scans-<account>-<region> |
Workflow
-
Pre-checks. Read config, verify agent space, resolve values.
-
Collect spec files. Identify the
requirements.mdand/ordesign.mdthe user is working on. Use absolute paths. Ask if unclear which files to review. -
Zip the workspace (same exclusions as code scan):
cd <absolute-workspace-path> zip -r /tmp/source.zip . \ -x ".git/*" -x ".security-agent/*" -x "node_modules/*" \ -x "__pycache__/*" -x ".venv/*" -x "venv/*" \ -x "dist/*" -x "build/*" -x "target/*" \ -x ".mypy_cache/*" -x ".pytest_cache/*" -x ".tox/*" \ -x ".next/*" -x "cdk.out/*" -x ".DS_Store" -x "*.pyc" -
Upload source zip:
SCAN_ID="tm-$(date +%s)-$(openssl rand -hex 3)" WORKSPACE_ID=$(printf '%s' "$(pwd)" | md5sum | cut -c1-12) aws s3 cp /tmp/source.zip s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip --expected-bucket-owner <account> -
Upload spec files:
aws s3 cp /path/to/requirements.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/requirements.md --expected-bucket-owner <account> aws s3 cp /path/to/design.md s3://<bucket>/security-scans/threat-models/${SCAN_ID}/specs/design.md --expected-bucket-owner <account> -
Create threat model:
aws securityagent create-threat-model --agent-space-id <id> --title <title> \ --service-role <role-arn> \ --assets sourceCode=[{s3Location=s3://<bucket>/security-scans/source/${WORKSPACE_ID}/source.zip}] \ --scope-docs '[{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/requirements.md"},{"s3Location":"s3://<bucket>/security-scans/threat-models/'${SCAN_ID}'/specs/design.md"}]'Capture
threatModelId. -
Start threat model job:
aws securityagent start-threat-model-job --agent-space-id <id> --threat-model-id <tm-id>Capture
threatJobId. -
Persist to
scans.jsonwithscan_type: "THREAT_MODEL". -
Tell user: "Threat model review started. Runtime varies with workspace size. I'll check every 2 minutes — say 'stop polling' to opt out."
-
Poll every 2 minutes:
aws securityagent batch-get-threat-model-jobs --agent-space-id <id> --threat-model-job-ids <tj-id>Only respond when status changes.
-
On COMPLETED → fetch threats:
aws securityagent list-threats --agent-space-id <id> --threat-job-id <tj-id>If
nextToken, paginate with--next-token.
Findings presentation
Each threat includes: statement, severity, stride category, threatImpact, recommendation, impactedAssets.
🟣 CRITICAL: {statement}
STRIDE: {stride}
Impact: {threatImpact}
Assets: {impactedAssets}
Recommendation: {recommendation}
🔴 HIGH: {statement}
...
Write full report to .security-agent/findings-{scan_id}.md. Call out any threat that represents a regression from the prior design.
Rules
- Threat model reviews are standalone — no prior scan needed
- Poll every 2 minutes, not faster
- At least one spec file is required
- Use absolute paths for workspace and spec files
- Title:
threat-model-<feature-name>(no spaces)
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

timestream-influxdb
Managed InfluxDB on AWS with guidance on engine selection, provisioning, schema design, and troubleshooting.

transitgateway
Configure AWS Transit Gateway to connect multiple VPCs and on-premises networks through a central hub.

troubleshooting-application-failures
Diagnose application failures by analyzing CloudWatch logs for error patterns and root causes.

troubleshooting-efs
Diagnose and resolve Amazon EFS mount failures, permissions, performance, and connectivity issues.

troubleshooting-s3-files
Diagnose and resolve Amazon S3 Files mount failures, permissions, sync, and performance issues.

waf
Configure AWS WAF to filter web traffic and protect applications from exploits, bots, and fraud.