AWS Security Agent adds threat modeling, Kiro power and Claude…
By Dillip Chowdary • Jul 20, 2026 • Source: AWS News Blog
**AWS Security Agent** now ships **STRIDE-based threat modeling**, full repository and pull-request **code scanning with remediation** across major Git platforms, and IDE-side access through **Kiro power**, a **Claude Code plugin**, and **MCP**. The AWS News Blog positions the release as a way for developers to run security reviews and apply fixes without leaving their normal tools.
On the product side, threat modeling follows the **STRIDE** categories so findings map to spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege rather than free-form notes. Scanning covers both whole repos and individual PRs, with remediation guidance attached to the results. The same agent surface is reachable from the IDE via **Kiro power**, the **Claude Code plugin**, and **MCP**, so reviews and fixes stay in the editor instead of a separate console hop.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders, the useful change is workflow, not another dashboard. Threat modeling and PR scanning land where code is written and reviewed; **MCP** and the plugin path mean existing agent-style coding setups can call security checks as part of the same session. That cuts context switching between design review, static findings, and the patch itself.
In market terms, this puts **AWS Security Agent** closer to the IDE-and-agent stack many teams already use—**Claude Code**, **MCP**-based tools, and in-editor assistants—while tying those surfaces to AWS’s own security product. Competing offerings often split threat modeling, repo scanning, and IDE plugins across products; here the pitch is one agent covering modeling, scan, and fix across major Git hosts.
What to watch next is whether teams adopt the **STRIDE** output as a standard input to design reviews and PR gates, and whether **Kiro power**, the **Claude Code plugin**, and **MCP** become the default path for remediation rather than portal-only workflows. Practical next step: wire the agent into a representative repo and PR path, run a threat model and a scan in the IDE, and judge whether remediation quality is strong enough to sit on the critical path of review.
Advertisement
🔎 More interesting news
- Capital One releases VulnHunter, an open-source AI tool that finds software flaws before…
- The Download: OpenAI unveils GPT-Red and heat pumps rise in the US
- AWS Releases Loom, an Open-Source Reference Platform for Governing AI Agents at…
- Apple releases first iOS 26.6 RC for iPhone
- Today's full Tech Pulse briefing →