Back to blog

Noma Power for Amazon Kiro: AI Security Context, Built Into Your Coding Agent

Gal Moyal

Nadav Lotan

August 26, 2026

Kiro is changing how fast development teams can go from concept to development to deploying an agent. That speed is the point, but it also means security needs to keep pace. Today, we're announcing the Noma Power for Kiro: a way to ask your coding agent what's risky about what you're building, and get a real answer, without leaving the workflow.

The problem: security context lives somewhere else

Developers building agents in Kiro move from idea through code, test, and deploy in a single session. But, security context is in another dashboard, behind a different login. Getting an answer means stopping what you're doing, opening that dashboard, finding the right security context, and copy-pasting the findings into a prompt.

Many developers skip that step. Not because they don't care about security, but because the friction is real much like the deadline. The agent ships and the security team finds out about it later. Multiply that across every team building on Kiro, and the gap between what's being built and what security knows about becomes the real risk.

The solution: Just ask Kiro

The Noma Power makes Noma's security posture, inventory, and findings available directly inside Kiro. There's no new scanning engine to stand up and no separate agent to deploy. Kiro calls Noma through a managed MCP connection, and the report appears in Kiro.  The report is available in .doc, .PDF or markdown format ready for you to read, share or add to a ticket.

The report is scoped to your Noma tenant, your full AI inventory as tracked by Noma, spanning every connected environment the user is entitled to, not just the AWS account or project you have open in Kiro.

What are Kiro Powers

Kiro powers bundle MCP tools, steering files, and hooks into a single install, giving your agents specialized knowledge without overwhelming them with context.

The Noma Power is built to answer three questions on demand:
  • What AI assets does this tenant have? A live view of the agents, models, MCP servers, and tools Noma is already tracking.
  • Where does exposure exist across those assets? Misconfigurations, excessive permissions, and risk patterns like toxic combinations of agentic capabilities specific to the agent you're building.
  • What should security and engineering teams do next? Findings are prioritized, so the answer is actionable the moment it lands.

Ask Kiro to run a report, and it comes back in markdown, PDF, or DOC, ready to read, share, or drop straight into a ticket.

What the Power reports

  • AI inventory across agents, toolsets, models, datasets, notebook files, and pipeline jobs
  • Open posture findings and exposure concentration
  • Ownership and accountability coverage
  • Agent and MCP tool surface
  • Model, dataset, notebook, and pipeline posture
  • AI-DR runtime application and protection-profile coverage
  • Overall status, seven posture dimensions, prioritized risks, positive signals, recommended actions, and data-confidence notes
Example Report Output
Example Report Output

Why security teams can trust it

The Noma Power installation is configuration and steering only.  Every request routes through Noma's managed MCP, authenticated with OAuth and PKCE, and scoped to only the tenants the requesting user is authorized for. Kiro never receives a credential, a token, or a raw identity claim.

And the Power is read-only by design. It can query inventory and findings. It cannot trigger a scan, modify code, touch a connector, or change a runtime policy. Whatever the report surfaces, acting on it stays with your security and engineering teams.

What is Kiro

Kiro is an agentic AI with an IDE, CLI, web interface, and mobile app that helps developers do their best work. From quick fixes to complex tasks, Kiro turns prompts into executable specs, validates code, finds bugs, and builds across large codebases with parallel agents that learn from every session. Kiro agents solve challenging problems, automate tasks, and keep working in the cloud when you step away.

Built with AWS

The Noma AI-SPM Power for Kiro was built in partnership with AWS. Noma is the first AI security vendor selected for AWS's Security Hub Extended program, and this integration extends that relationship into the coding agent itself. It's the same AI-SPM engine relied on by Fortune 500 teams across financial services, pharma, insurance, and technology, now reachable directly from Kiro.

Get started

Installing the Power takes a few minutes:

1. Open the Kiro Powers Catalog.

2. Search for the Noma AI-SPM Power.

3. Select Install.

4. Complete browser authentication with your existing Noma account.

5. Ask Kiro to run a Noma AI-SPM report for your tenant.

From there, security posture is just another question you can ask the agent you're already using.

Learn more about Noma

READ TIME
9 min
CATEGORY
Partnerships
TABLE OF CONTENTS
100%
Share this:

Discover more

Partnerships

Noma Power for Amazon Kiro: AI Security Context, Built Into Your Coding Agent

Gal Moyal

Nadav Lotan

August 26, 2026

Partnerships

Noma Security Is Now a Native Guardrail Across the TrueFoundry Stack

Gal Moyal

Nadav Lotan

August 17, 2026

News

What the NVIDIA Open Secure AI Alliance Means for Organizations

Gal Moyal

Batya Steinherz

July 28, 2026