threat-modeling-with-aws-security-agent
An agent skill by aws, from aws/agent-toolkit-for-aws. Tags: analysis, design, security, threat-modeling, validation.
What it does
Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review requirements.md or design.md for security posture changes, or STRIDE analysis.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add aws/agent-toolkit-for-aws --skill threat-modeling-with-aws-security-agent
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws
cp -r agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent ~/.claude/skills/threat-modeling-with-aws-security-agent
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- aws/agent-toolkit-for-aws (all skills from this repository)
- Path
- plugins/aws-agents-for-devsecops/skills/threat-modeling-with-aws-security-agent/SKILL.md
- Branch
- main
- Collection
- aws-agents-for-devsecops
- Updated
- 2026-09-19
Related skills
- fp-check — Systematically verifies suspected security bugs to eliminate false positives.
- post-patch-validation — Validates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation.
- seo-technical — Technical SEO audit across 9 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured data, JavaScript rendering.
- sharp-edges — Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes.
- qa-expert — This skill should be used when establishing comprehensive QA testing processes for any software project.
- diff-scanning-with-aws-security-agent — Run a fast AWS Security Agent diff scan on only the changed code since a git ref.