AWS Security Agent adds threat modeling, Kiro power, Claude Code plugin, and more
AWS Security Agent now adds STRIDE-based threat modeling, full repo and PR code scanning with remediation across major Git platforms, and IDE integrations via Kiro power, Claude Code plugin, and MCP — letting developers run security reviews and fix issues without context switching.
At re:Invent 2025, AWS previewed AWS Security Agent, now part of AWS Continuum, which proactively secures applications throughout the development lifecycle across all environments. It enables on-demand penetration testing customized to applications, discovering and reporting verified security risks. Since preview, AWS announced general availability for on-demand penetration testing and previewed full repository code review for deep, context-aware security analysis. New features based on customer feedback include code review updates with pull request scanning, remediation, security requirements packs, simulated validation, and integrations with GitHub, GitLab, Bitbucket, and Confluence. Threat modeling (preview) analyzes design documents or source code to identify threats using the STRIDE framework with recommended mitigations. Kiro power, Claude Code plugin, and MCP integration enable running code reviews, threat models, and remediation directly from IDEs or CLI with inline results. Code review updates support SaaS and self-hosted GitLab and Bitbucket, plus Confluence integration for documentation context. The agent performs deep reasoning-based analysis on pull requests and full repositories, checking organizational security requirements and common risks, validating findings in simulated environments, and providing fix commits and remediation guidance in workflows. Design review updates allow continuous validation of security requirements using managed compliance packs like AWS Well Architected Framework, NIST CSF, PCI DSS, or custom organizational requirements. Threat modeling generates models from design docs or code, mapping application components, threat actors, attack vectors, and prioritizing threats. Kiro power and Claude Code plugin integrate with AI IDEs via MCP, enabling threat models and code reviews inline. Kiro power uses the AWS Security Agent MCP server, supports commands like "Set up AWS Security Agent," "Run a full security scan on this repo," and "help me remediate my findings," facilitating vulnerability detection, remediation, and bugfix sessions within familiar IDEs. Threat models generated by Kiro power are saved locally. AWS Security Agent now covers design-time security (design reviews, threat modeling), development-time security (code review), and deployment-time security (penetration testing) in a unified offering. Features are available in AWS commercial regions with pricing and trial offers on the AWS Security Agent pricing page. Feedback can be sent via AWS re:Post or AWS Support contacts. Updated June 18, 2026, with the launch of Claude Code plugin for AWS DevOps Agent and AWS Security Agent.