npx skills add ...
npx skills add aws/agent-toolkit-for-aws --skill diff-scanning-with-aws-security-agent
npx skills add aws/agent-toolkit-for-aws --skill diff-scanning-with-aws-security-agent
Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.
Scan only the code that changed since a git ref. Faster than a full scan — focuses findings on the diff. No prior full scan needed.
Read .security-agent/config.json for agent_space_id and region. If missing, run the setup-security-agent workflow inline first.
Track scans in .security-agent/scans.json.
| Placeholder | How to resolve |
|---|---|
<id> (agent space) | config.agent_space_id |
<region> | config.region (default us-east-1) |
<account> | aws sts get-caller-identity --query Account --output text |
<role-arn> | arn:aws:iam::<account>:role/SecurityAgentScanRole |
<bucket> | security-agent-scans-<account>-<region> |
<WORKSPACE_ID> | printf '%s' "$(pwd)" | md5sum | cut -c1-12 |
Pre-scan checks. Same as full scan — read config, verify agent space, resolve values, generate workspace ID.
Ask what to scan against:
BASE_REF=HEAD (default)BASE_REF=mainGenerate diff (fail fast if empty):
Zip the workspace (same exclusions as full scan, 2 GB limit):
Upload both source zip and diff patch:
Get or create per-workspace CodeReview (same logic as full scan — lookup config.json → code_reviews[<abs_path>], create if absent):
Start the diff job:
If ResourceNotFoundException: recreate CodeReview and retry.
Capture codeReviewJobId. Persist to scans.json with scan_type: "DIFF" and base_ref.
Tell user: "Diff scan started. Takes a few minutes. I'll check every 2 minutes — say 'stop polling' to opt out."
Poll every 2 minutes:
Only respond when status changes. On COMPLETED → fetch findings.
Findings: same presentation as full scan — grouped by severity, report written to .security-agent/findings-{scan_id}.md.
BASE_REF=HEAD if user doesn't specifydiff-<git-branch>-<timestamp> (no spaces)