Amazon Web Services (AWS) today announced a significant expansion of its AWS Security Agent, now an integral part of AWS Continuum, introducing advanced features designed to embed security proactively throughout the entire software development lifecycle. These updates include enhanced code review capabilities with broader version control system support and AI-driven deep analysis, a robust new threat modeling functionality, and seamless integration into developer workflows via the Kiro power and a Claude Code plugin, directly addressing critical needs for modern DevSecOps practices.
A Proactive Approach to Application Security
The journey of AWS Security Agent began at re:Invent 2025, where it was first previewed as a frontier agent engineered to secure applications from design to deployment across diverse environments. Its initial promise was to enable on-demand penetration testing customized to specific applications, uncovering and validating security risks through exploitability testing. Following this initial preview, AWS steadily rolled out key components, with on-demand penetration testing achieving general availability in March 2026. This was quickly followed by the preview of full repository code review in May 2026, which offered deep, context-aware security analysis across an entire codebase.

Today’s announcement represents a substantial leap forward, driven by extensive customer feedback and a clear vision for integrated, intelligent security. The newly introduced features aim to further "shift left" security, making it an intrinsic part of development rather than a post-development bottleneck. This strategy is increasingly vital in a landscape where cyber threats are escalating, and the cost of identifying and remediating vulnerabilities late in the development cycle can be exponentially higher. Industry analyses consistently highlight that security flaws introduced during the design and coding phases are the most prevalent, underscoring the necessity of tools that can identify and mitigate these risks early.
Enhanced Code Review: Broader Reach and Deeper Insight
The updated code review features significantly broaden the AWS Security Agent’s applicability and analytical depth. Developers and security teams can now connect to a wider array of version control systems, including GitLab and Bitbucket, alongside the existing GitHub support. Crucially, this compatibility extends to both SaaS and self-hosted versions of these platforms, ensuring that organizations can leverage the agent regardless of their chosen code hosting infrastructure. This expanded integration is vital for enterprises with heterogeneous development environments or strict data residency requirements.
Furthermore, the integration with Confluence allows the agent to reference existing documentation as contextual input for code reviews. This capability enables the agent to understand project-specific security requirements, architectural decisions, and other relevant information, leading to more accurate and context-aware vulnerability detection. Rather than relying solely on generic rules, the agent can now perform "deep, reasoning-based analysis" on every pull request and full repository scans. This goes beyond traditional pattern-matching, identifying complex vulnerabilities that might otherwise evade detection by conventional static analysis tools. By checking code against organizational security requirements and common security risks, AWS Security Agent aims to catch subtle flaws often missed by less sophisticated solutions.

The practical workflow for developers is also significantly streamlined. Upon identifying a vulnerability, the agent delivers fix commits and comprehensive remediation guidance directly within the developer’s GitHub, GitLab, or Bitbucket workflow. This inline feedback loop minimizes context switching for developers, accelerating the remediation process. For security teams, the ability to configure monitored repositories and intervene on critical issues ensures centralized oversight and control. A standout feature is the agent’s capacity to validate findings in simulated environments, demonstrating proof of exploitability. This not only confirms the severity of a vulnerability but also provides concrete evidence that helps developers understand the impact and prioritize fixes, effectively embedding security expertise directly into the development pipeline and reducing security-related delays.
Design Review Updates: Built-in Compliance and Best Practices
Securing applications effectively begins long before a single line of code is written. Recognizing this, AWS Security Agent’s design review capabilities have been enhanced to continuously validate security requirements across design and code reviews with new managed compliance packs. These packs include industry-standard frameworks such as the AWS Well-Architected Framework, NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), PCI DSS (Payment Card Industry Data Security Standard), and general AWS best practices.
Organizations can also import their own internal security requirements directly from internal documents or integrate with Confluence. This flexibility ensures that the agent’s design reviews align perfectly with an organization’s specific regulatory and operational mandates. A key benefit is that every finding from a design review is mapped back to the organization’s compliance posture. This continuous alignment means that development teams remain audit-ready throughout the building process, reducing the last-minute scramble and potential rework often associated with compliance checks. This proactive approach to compliance not only mitigates risk but also fosters a culture of security by design.

Introducing Threat Modeling: A Foundational Security Practice
A groundbreaking addition to the AWS Security Agent’s suite is its new threat modeling capability. This feature automates the traditionally manual and often complex process of identifying potential threats to an application. The agent generates comprehensive threat models based on an application’s design documentation or existing code repository. It constructs a rich context about the application, encompassing data flows, architectural components, and trust boundaries.
By mapping out all components of an application, the agent can intelligently identify potential threat actors and their corresponding attack vectors. It then determines where weaknesses may exist within the system and, crucially, prioritizes these threats. This prioritization is critical for development and security teams, enabling them to focus their resources on addressing the most impactful risks first. Automating threat modeling accelerates a fundamental security practice, making it more accessible and scalable, particularly for rapidly evolving microservices architectures and complex cloud-native applications where manual threat modeling can be prohibitively time-consuming.
AI-Powered Integrations: Kiro power and Claude Code Plugin

In a significant move towards deeply embedding security into the developer’s native environment, AWS Security Agent introduces a new Kiro power and a Claude Code plugin. These integrations allow the agent to connect with any AI-powered Integrated Development Environment (IDE) through an open MCP (Meta-programming Platform) integration. This represents a strategic alignment with the growing trend of AI-assisted development, ensuring that security analysis is not an afterthought but an intrinsic part of the coding process.
The Kiro power, an open-source tool, enables developers to trigger threat models and code reviews directly from their IDE. Results surface inline, eliminating the need for context switching and allowing developers to address security findings without leaving their familiar workspace. Setting up the AWS Security Agent is simplified through Kiro, which can check for existing Agent Spaces or prompt for the creation of a new one.
Developers can leverage natural language prompts, such as "Run a full security scan on this repo," to initiate comprehensive code analyses. The Kiro power includes an Agent hook that can automatically trigger a code review diff scan after the Kiro agent completes its turn, ensuring continuous security evaluation. For pre-production environments, developers can run penetration tests directly from their CLI, detecting vulnerabilities that often bypass conventional scanners. The agent’s ability to validate findings and generate ready-to-implement code fixes further streamlines the remediation process.
The Kiro power also assists in remediation. By asking "help me remediate my findings," developers can download findings to their local workspace, prioritize critical issues, and initiate bugfix spec sessions. This allows developers to iterate on fixes using their existing IDE tooling, steering, and MCP servers, making security remediation a seamless extension of their development workflow. Similarly, threat models can be generated within the IDE by simply asking "Build a threat model for this application," with the output saved to .security-agent/threat_model.md.

The launch of the AWS Agents for DevSecOps, the Claude Code plugin for AWS DevOps Agent and AWS Security Agent, further solidifies AWS’s commitment to AI-driven security. This integration allows users of Claude Code to seamlessly incorporate security checks and threat analysis into their AI-assisted coding practices, marking a significant step towards truly intelligent DevSecOps.
Broader Impact and Strategic Implications
The comprehensive updates to AWS Security Agent underscore AWS’s commitment to advancing the DevSecOps paradigm. By unifying design-time security (design reviews and threat modeling), development-time security (code review), and deployment-time security (penetration testing) into a single, agentic offering, AWS provides a holistic solution that spans the entire software development lifecycle. This integration helps organizations shift from reactive security measures to a proactive, preventative posture, reducing the attack surface and mitigating risks earlier.
For development teams, these enhancements translate to faster, more secure coding with less friction. The embedded security feedback, automated fixes, and integrated compliance checks empower developers to build secure applications from the ground up without becoming security experts themselves. For security teams, the AWS Security Agent offers unprecedented visibility into the security posture of applications at every stage, reducing manual workload, ensuring audit readiness, and enabling them to focus on high-level strategic risks rather than tactical vulnerability hunting.

From an organizational perspective, the AWS Security Agent facilitates faster time-to-market for applications by minimizing security-related delays, while simultaneously enhancing the overall security and compliance of their digital assets. The emphasis on AI-powered integrations and open standards like MCP positions AWS Security Agent as a forward-looking solution in the rapidly evolving cybersecurity landscape, ready to adapt to new development methodologies and AI-driven workflows.
These features are now available in AWS commercial Regions where AWS Security Agent is supported. Detailed information on regional availability and future roadmap can be found on the AWS Capabilities by Region page. To encourage adoption, AWS is offering a 2-month free trial, with detailed pricing available on the AWS Security Agent pricing page. Customers are encouraged to provide feedback through the Security Agent console or AWS re:Post for Security Agent.
This release not only strengthens AWS’s position in the DevSecOps toolchain but also sets a new benchmark for how integrated and intelligent application security can be. As organizations continue to accelerate their digital transformation, tools like the AWS Security Agent will be critical in ensuring that innovation does not come at the expense of security.
