scanning-with-aws-security-agent
An agent skill by aws, from aws/agent-toolkit-for-aws. Tags: cloud, code-review, scanning, security, validation.
What it does
Run an AWS Security Agent scan on the workspace — uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked, verified findings with code locations and remediations. Use when the user asks to scan code, find vulnerabilities, run a security scan or review, check security issues, check scan status, show findings, list recent scans, or stop a scan.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add aws/agent-toolkit-for-aws --skill scanning-with-aws-security-agent
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws
cp -r agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/scanning-with-aws-security-agent ~/.claude/skills/scanning-with-aws-security-agent
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- aws/agent-toolkit-for-aws (all skills from this repository)
- Path
- plugins/aws-agents-for-devsecops/skills/scanning-with-aws-security-agent/SKILL.md
- Branch
- main
- Collection
- aws-agents-for-devsecops
- Updated
- 2026-09-19
Related skills
- diff-scanning-with-aws-security-agent — Run a fast AWS Security Agent diff scan on only the changed code since a git ref.
- pentesting-with-aws-security-agent — Run an AWS Security Agent penetration test against a live web application — registers and verifies the target domain.
- agents-harden — Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle.
- agents-pay — Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments.
- aws-cloudformation — Authors, validates, and troubleshoots AWS CloudFormation templates.
- aws-iam — Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits.