{"id":106199,"date":"2025-12-23T12:14:24","date_gmt":"2025-12-23T10:14:24","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=106199"},"modified":"2026-04-09T14:09:25","modified_gmt":"2026-04-09T12:09:25","slug":"bringing-ide-native-appsec-to-kiro-with-checkmarx-developer-assist","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/","title":{"rendered":"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist"},"content":{"rendered":"<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">\n<strong>Why Kiro and IDE-Native AppSec Matter<\/strong>&nbsp;<\/h2>\n\n\n\n<p>New IDEs&nbsp;don\u2019t&nbsp;change how developers think about&nbsp;security,&nbsp;they change how fast security problems appear.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/kiro.dev\/about\/\">Kiro<\/a>, an agentic development environment built by Amazon Web Services (AWS), is gaining attention because it fits neatly into modern development workflows: fast feedback, AI-assisted coding, and a familiar Visual Studio Code\u2013based experience.<br><br>But as with any productivity-focused Integrated Development Environment (IDE), increased speed also means increased risk. Code is written faster, dependencies are introduced more often, and vulnerabilities surface earlier in the lifecycle.&nbsp;<\/p>\n\n\n\n<p>That puts pressure on security tooling to meet developers where they already work.&nbsp;<\/p>\n\n\n\n<p>For&nbsp;developers and software builders&nbsp; the requirement is straightforward:&nbsp;<br>security controls must function\u202f<em>inside the IDE<\/em>, not downstream in CI\/CD pipelines or external dashboards. Developers should be able to&nbsp;identify&nbsp;issues as code is written, understand the impact, and move forward without context switching.&nbsp;<\/p>\n\n\n\n<p>The good news is that adopting a new IDE like Kiro does not require rethinking your security tooling from scratch. If an IDE is built on VS Code foundations, existing IDE-native security workflows can carry&nbsp;over with&nbsp;minimal friction.&nbsp;<\/p>\n\n\n\n<p>This post walks through how to use&nbsp;Checkmarx&nbsp;inside Kiro today,&nbsp;covering installation, configuration, and running real security scans directly in the IDE&nbsp;without relying on proprietary APIs, special agent commands, or experimental integrations.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">\n<br><strong>Installing the\u00a0Checkmarx\u00a0Developer Assist\u00a0in Kiro<\/strong>\u00a0<\/h2>\n\n\n\n<p>Checkmarx\u00a0Developer Assist is delivered to developers through the\u00a0Checkmarx\u00a0IDE extension, which can be installed directly in Kiro.\u00a0<\/p>\n\n\n\n<p>From within the Kiro IDE, open the Extensions view and search for\u202fCheckmarx. Install the official\u00a0Checkmarx\u00a0extension, which enables\u00a0Checkmarx\u00a0Developer Assist capabilities inside the editor. The same extension is used across supported VS Code based IDEs, allowing developers to bring Assist into their existing workflows without\u00a0additional\u00a0setup.\u00a0<\/p>\n\n\n\n<p>After installation, the extension prompts you to authenticate and connect to your\u00a0Checkmarx\u00a0environment. Once authenticated,\u00a0Checkmarx\u00a0Developer Assist becomes active for the open workspace, using your existing tenant configuration and security policies.\u00a0<\/p>\n\n\n\n<p>No Kiro specific configuration is&nbsp;required. Assist&nbsp;operates&nbsp;within the IDE, analyzing the code and dependencies in your active project and&nbsp;providing&nbsp;security insight directly where development happens.&nbsp;<\/p>\n\n\n\n<p>With the extension installed and connected,\u00a0Checkmarx\u00a0Developer Assist is ready to support secure development inside Kiro.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"936\" height=\"231\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-3.png\" alt=\"Checkmarx Assist extension in Kiro \" class=\"wp-image-106200\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-3.png 936w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-3-300x74.png 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-3-768x190.png 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-3-400x99.png 400w\" sizes=\"(max-width: 936px) 100vw, 936px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">\u00a0<br><strong>Getting\u00a0Checkmarx\u00a0Developer Assist Ready in Your Workspace<\/strong>\u00a0<\/h2>\n\n\n\n<p>Once the\u00a0Checkmarx\u00a0extension is installed, getting started with\u00a0Checkmarx\u00a0Developer Assist in Kiro is intentionally simple.\u00a0<\/p>\n\n\n\n<p>After signing in to your\u00a0Checkmarx\u00a0One environment, the extension uses the open workspace in Kiro as the context for analysis. There is no need for developers to manually create or configure projects inside the IDE.\u00a0Checkmarx\u00a0Developer Assist analyzes the source code and dependencies present in the workspace and\u00a0applies\u00a0your organization\u2019s existing security policies automatically.\u00a0<\/p>\n\n\n\n<p>Security rules, thresholds, and policy logic are inherited from&nbsp;Checkmarx&nbsp;One, so developers do not need to manage or customize security settings locally. This keeps the experience lightweight while ensuring that the guidance provided by Assist aligns with how your organization defines risk.&nbsp;<\/p>\n\n\n\n<p>With authentication complete and a workspace open,\u00a0Checkmarx\u00a0Developer Assist is ready to\u00a0provide\u00a0security insight as developers write and review code in Kiro.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">\n<strong>Using\u00a0Checkmarx\u00a0Developer Assist During Development in Kiro<\/strong>\u00a0<\/h2>\n\n\n\n<p>With\u00a0Checkmarx\u00a0Developer Assist active in the workspace, security analysis becomes part of the normal development flow inside Kiro.\u00a0<\/p>\n\n\n\n<p>As developers write or review code, Assist analyzes the source files and dependencies in the open workspace and surfaces security findings directly in the IDE. These insights are presented with context, including severity and location, helping developers understand potential risk without leaving their editor.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"936\" height=\"340\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-5.png\" alt=\"Checkmarx One Developer Assist scanning in real time from within the Kiro IDE\" class=\"wp-image-106202\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-5.png 936w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-5-300x109.png 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-5-768x279.png 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-5-400x145.png 400w\" sizes=\"(max-width: 936px) 100vw, 936px\" \/><figcaption class=\"wp-element-caption\">Checkmarx Developer Developer Assist scanning in real time from within the Kiro IDE<\/figcaption><\/figure>\n\n\n\n<p>Rather than acting as a separate security step, Assist supports developers as they work, highlighting issues early and reducing the likelihood of discovering problems later in the pipeline. Because the analysis is based on the current state of the workspace, the feedback developers receive is directly tied to the code they are editing.&nbsp;<\/p>\n\n\n\n<p>Checkmarx\u00a0Developer Assist focuses on visibility and understanding. It helps developers\u00a0identify\u00a0insecure patterns and vulnerable dependencies as they appear, using the same policies and rules defined in\u00a0Checkmarx\u00a0One. This ensures that the guidance provided in Kiro reflects organizational standards without requiring developers to manage security settings themselves.\u00a0<\/p>\n\n\n\n<div style=\"left: 0; width: 100%; height: 0; position: relative; padding-bottom: 56.338%;\"><iframe src=\"https:\/\/player.vimeo.com\/video\/1150397529?app_id=122963\" style=\"top: 0; left: 0; width: 100%; height: 100%; position: absolute; border: 0;\" allowfullscreen scrolling=\"no\" allow=\"encrypted-media *;\"><\/iframe><\/div>\n\n\n\n<div style=\"height:43px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>By bringing security insight directly into the IDE,\u00a0Checkmarx\u00a0Developer Assist enables teams to move quickly while\u00a0maintaining\u00a0confidence in the code they are producing.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">\n<strong>Reviewing Assist Insights in&nbsp;Checkmarx&nbsp;One<\/strong>&nbsp;<\/h2>\n\n\n\n<p>While\u00a0Checkmarx\u00a0Developer Assist delivers security insight directly in Kiro, the same findings are also available in\u00a0Checkmarx\u00a0One for broader visibility and coordination.\u00a0<\/p>\n\n\n\n<p>As analysis runs against the code in the&nbsp;developer&nbsp;workspace, results are reflected in&nbsp;Checkmarx&nbsp;One, where AppSec and engineering teams can review findings across projects and contributors. This&nbsp;provides&nbsp;a centralized view of security risk without requiring developers to change how they work in the IDE.&nbsp;<\/p>\n\n\n\n<p>Checkmarx&nbsp;One preserves the context surfaced by Assist, including severity and vulnerability details, making it easier for teams to track patterns, understand risk trends, and align remediation efforts across the organization. Developers see issues as they write code, while security teams gain visibility into what is happening across repositories and teams.&nbsp;<\/p>\n\n\n\n<p>This shared visibility helps bridge the gap between development and security. Developers receive&nbsp;timely&nbsp;feedback inside Kiro, and AppSec teams&nbsp;retain&nbsp;the governance and reporting capabilities they need, all grounded in the same policies and&nbsp;analysis&nbsp;logic.&nbsp;<\/p>\n\n\n\n<p>By combining IDE level insight with platform level visibility,\u00a0Checkmarx\u00a0Developer Assist supports secure development without fragmenting workflows or forcing teams into separate tools.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"936\" height=\"222\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-4.png\" alt=\"Reviewing scanning results in Checkmarx One \" class=\"wp-image-106201\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-4.png 936w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-4-300x71.png 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-4-768x182.png 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-4-400x95.png 400w\" sizes=\"(max-width: 936px) 100vw, 936px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\">\n<strong>Bringing Security Into AI-Assisted Development with Kiro<\/strong>&nbsp;<\/h2>\n\n\n\n<p>AI-assisted IDEs like Kiro are changing how developers write code. Faster iteration, smarter suggestions, and tighter feedback loops are becoming the norm. As development accelerates, security needs to keep pace without adding friction or slowing teams down.&nbsp;<\/p>\n\n\n\n<p>Checkmarx\u00a0Developer Assist brings security insight directly into that workflow. By\u00a0operating\u00a0inside the IDE, Assist helps developers understand risk as code is written, using the same policies and standards defined across the organization. There is no need to wait for pipeline feedback or switch tools to gain visibility.\u00a0<\/p>\n\n\n\n<p>With\u00a0Checkmarx\u00a0Developer Assist running in Kiro, teams can adopt new development experiences with confidence, knowing that security\u00a0remains\u00a0part of the process from the first line of code.\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>Why Kiro and IDE-Native AppSec Matter&nbsp; New IDEs&nbsp;don\u2019t&nbsp;change how developers think about&nbsp;security,&nbsp;they change how fast security problems appear.&nbsp; Kiro, an agentic development environment built by Amazon Web Services (AWS), is gaining attention because it fits neatly into modern development workflows: fast feedback, AI-assisted coding, and a familiar Visual Studio Code\u2013based experience. But as with any [&hellip;]<\/p>\n","protected":false},"author":83,"featured_media":106203,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[85,84,1424,1283,1280],"tags":[304,1516,1452,421,492,1473],"class_list":["post-106199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security-trends","category-blog","category-checkmarx-one","category-checkmarx-product-use-cases-guides","category-secure-coding-best-practices-for-developers","tag-aws","tag-checkmarx-developer-assist","tag-developer-assist","tag-developer-experience","tag-ide-scanning","tag-kiro"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist<\/title>\n<meta name=\"description\" content=\"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist\" \/>\n<meta property=\"og:description\" content=\"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-23T10:14:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-09T12:09:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2240\" \/>\n\t<meta property=\"og:image:height\" content=\"1260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Steve Boone\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Steve Boone\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\"},\"author\":{\"name\":\"Steve Boone\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/b18c949667890c9cc96de7d4d274fdd6\"},\"headline\":\"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist\",\"datePublished\":\"2025-12-23T10:14:24+00:00\",\"dateModified\":\"2026-04-09T12:09:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\"},\"wordCount\":1108,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp\",\"keywords\":[\"AWS\",\"Checkmarx Developer Assist\",\"developer assist\",\"developer experience\",\"IDE Scanning\",\"Kiro\"],\"articleSection\":[\"Application Security Trends &amp; Insights\",\"Blog\",\"Checkmarx One\",\"Checkmarx Product News, Use Cases &amp; Guides\",\"Secure Coding Best Practices for Developers\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\",\"name\":\"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp\",\"datePublished\":\"2025-12-23T10:14:24+00:00\",\"dateModified\":\"2026-04-09T12:09:25+00:00\",\"description\":\"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp\",\"width\":2240,\"height\":1260},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/b18c949667890c9cc96de7d4d274fdd6\",\"name\":\"Steve Boone\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_83.jpeg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_83.jpeg\",\"caption\":\"Steve Boone\"},\"url\":\"https:\/\/checkmarx.com\/author\/steveboone\/\"}]}<\/script>\n<meta property=\"og:video\" content=\"https:\/\/player.vimeo.com\/video\/1150397529\" \/>\n<meta property=\"og:video:type\" content=\"text\/html\" \/>\n<meta property=\"og:video:duration\" content=\"468\" \/>\n<meta property=\"og:video:width\" content=\"426\" \/>\n<meta property=\"og:video:height\" content=\"240\" \/>\n<meta property=\"ya:ovs:adult\" content=\"false\" \/>\n<meta property=\"ya:ovs:upload_date\" content=\"2025-12-23T10:14:24+00:00\" \/>\n<meta property=\"ya:ovs:allow_embed\" content=\"true\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist","description":"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/","og_locale":"en_US","og_type":"article","og_title":"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist","og_description":"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.","og_url":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2025-12-23T10:14:24+00:00","article_modified_time":"2026-04-09T12:09:25+00:00","og_image":[{"width":2240,"height":1260,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp","type":"image\/webp"}],"author":"Steve Boone","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Steve Boone","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/"},"author":{"name":"Steve Boone","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/b18c949667890c9cc96de7d4d274fdd6"},"headline":"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist","datePublished":"2025-12-23T10:14:24+00:00","dateModified":"2026-04-09T12:09:25+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/"},"wordCount":1108,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp","keywords":["AWS","Checkmarx Developer Assist","developer assist","developer experience","IDE Scanning","Kiro"],"articleSection":["Application Security Trends &amp; Insights","Blog","Checkmarx One","Checkmarx Product News, Use Cases &amp; Guides","Secure Coding Best Practices for Developers"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/","url":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/","name":"Bringing IDE-Native AppSec to Kiro with Checkmarx Developer Assist","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp","datePublished":"2025-12-23T10:14:24+00:00","dateModified":"2026-04-09T12:09:25+00:00","description":"As Kiro accelerates development, IDE-native security becomes critical. See how Checkmarx Developer Assist brings AppSec directly into Kiro.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/bringing-ide-native-appsec-to-kiro-with-checkmarx-one-assist\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/One-Assist.webp","width":2240,"height":1260},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/b18c949667890c9cc96de7d4d274fdd6","name":"Steve Boone","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_83.jpeg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_83.jpeg","caption":"Steve Boone"},"url":"https:\/\/checkmarx.com\/author\/steveboone\/"}]},"og_video":"https:\/\/player.vimeo.com\/video\/1150397529","og_video_type":"text\/html","og_video_duration":"468","og_video_width":"426","og_video_height":"240","ya_ovs_adult":"false","ya_ovs_upload_date":"2025-12-23T10:14:24+00:00","ya_ovs_allow_embed":"true"},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/106199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/83"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=106199"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/106199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/106203"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=106199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=106199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=106199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}