aws-agents-for-devsecops Claude Code Plugin
Claude Code PluginClaude CodeDevelopmentSecurity, Auth & ComplianceCloud, Deployment & CI/CDMonitoring & ObservabilityThe explanation below is AI-generated. Please verify it against the sources.
This plugin connects Claude Code to AWS DevOps Agent and AWS Security Agent, enabling incident investigation, code review for release readiness, vulnerability scanning, and penetration testing. It communicates with these agents through a remote MCP server that requires AWS SigV4 credentials or an access token for authentication. A set of skills auto-trigger based on context, such as incident keywords or release testing requests, while explicit slash commands cover setup, chat, investigation, release testing/readiness, cost queries, and multi-AgentSpace management. The README also documents dozens of remote tools for chat, investigation, release testing, recommendations, agent space management, and evaluation. It explicitly warns that any commands or scripts returned by the DevOps agent must never be auto-executed and require user approval first.
About the service
AWS DevOps Agent and AWS Security Agent are remote AWS services accessed over a network connection using AWS account credentials. The DevOps agent handles operational tasks like incident investigation, chat-based queries, and release testing/readiness reviews, while the Security Agent handles code scanning, penetration testing, threat modeling, and remediation of security findings.
What you can do with aws-agents-for-devsecops
- Set up authentication for AWS DevOps Agent and AWS Security Agent using dedicated setup skills or commands
- Investigate production incidents through auto-triggered or explicit commands
- Chat with the DevOps agent about cost, architecture, or topology questions
- Create and monitor release UI/API testing jobs
- Run pre-merge release readiness reviews with risk analysis
- Coordinate operations across multiple AgentSpaces or AWS accounts
- Run full or diff-only code security scans
- Execute penetration tests against live endpoints
- Perform STRIDE-based threat model reviews on design documents
- Fetch, triage, and remediate security findings