---
title: "aws-agents-for-devsecops"
description: "Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent."
canonical: https://agentpluginsdirectory.com/plugins/aws-agents-for-devsecops
last-updated: 2026-09-21
---

# aws-agents-for-devsecops
Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.
- Slug: aws-agents-for-devsecops
- Publisher: Amazon Web Services
- Repository: https://github.com/aws/agent-toolkit-for-aws
- Manifest: plugins/aws-agents-for-devsecops/plugin.json
- Version: 1.1.0
- License: Apache-2.0
- Category (editorial): security
- Skills: 13 (analyzing-release-readiness, chatting-with-aws-devops-agent, coordinating-multi-space-devops-agent, diff-scanning-with-aws-security-agent, investigating-incidents-with-aws-devops-agent, pentesting-with-aws-security-agent, remediating-with-aws-security-agent, running-release-tests, scanning-with-aws-security-agent, setup-devops-agent, setup-security-agent, setup, threat-modeling-with-aws-security-agent)
- MCP servers: 0
- Stars: 2687
- Repository created: 2026-04-23
- Repository last pushed: 2026-09-21
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/aws-agents-for-devsecops
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What aws-agents-for-devsecops does, in the publisher's words

Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.

AWS SigV4 credentials for your AWS account. For the DevOps agent, you may alternatively use an access token.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/aws/agent-toolkit-for-aws/HEAD/plugins/aws-agents-for-devsecops/README.md

## Skills

- analyzing-release-readiness: Trigger a pre-merge release readiness review on a GitHub PR, GitLab MR, or local branch. Use when the user wants to analyze code changes for risk, correctness, and potential rollback issues before merging. Trigger words include release readiness, analyze PR, analyze MR, review PR, risk analysis, pr…
- chatting-with-aws-devops-agent: Have a fast, conversational analysis with the AWS DevOps Agent. Use for cost optimization, architecture review, topology mapping, knowledge / runbook discovery, security audits, dependency questions, and quick diagnostics, anything that needs a 5-30 second answer rather than a 5-8 minute deep inve…
- coordinating-multi-space-devops-agent: Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session, route questions to the right space (prod vs staging vs knowledge), query several spaces in parallel and synthesize, or compare findings across accounts. Use whenever the user has more than one AgentSpace conf…
- diff-scanning-with-aws-security-agent: Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.
- investigating-incidents-with-aws-devops-agent: Run a deep root-cause investigation on the AWS DevOps Agent. Use when the user describes an incident, alarm, outage, or unexplained behavior, keywords like "5xx", "503", "OOM", "latency spike", "deployment failure", "rollback", "sev1", "investigate", "root cause", "debug", "alarm fired", "service…
- pentesting-with-aws-security-agent: Run an AWS Security Agent penetration test against a live web application, registers and verifies the target domain, exercises the supplied endpoints with the managed Security Agent service, and returns verified runtime findings. Use when the user asks to pentest, run a penetration test, test thei…
- remediating-with-aws-security-agent: Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results, code review findings, vulnerabilities found in their AWS account, "what did the security scan find…
- running-release-tests: Run automated release testing (UI or API) via the AWS DevOps Agent using a pre-configured test profile. Use when the user wants to validate multi-step workflows, verify features, check for regressions, or test API endpoints. Trigger words include run tests, UAT, test my app, test profile, UI test,…
- scanning-with-aws-security-agent: Run an AWS Security Agent scan on the workspace, uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked, verified findings with code locations and remediations. Use when the user asks to scan code, find vulnerabilities, run a security scan or review, check…
- setup-devops-agent: Setup and diagnostics for the AWS DevOps Agent MCP connection. Triggers when aws-devops-agent is missing from.mcp.json, when the connection is broken, or when the user says "set up devops agent" / "configure agent". Does NOT trigger if the MCP is already connected and working.
- setup-security-agent: Configure AWS Security Agent for the current workspace, provision or reuse an agent space, IAM service role, and S3 bucket. Use when the user asks to "set up security agent", "configure security scanner", "is security agent configured", or on first-time use before any scan or pentest.
- setup: Set up the AWS DevOps Agent and AWS Security Agent connections. Use when the user says "set up", "configure", "connect", or when MCP tools are missing.
- threat-modeling-with-aws-security-agent

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
