Agentic AI CodeSentinel-Code Review, Dependency & Security analysis
HCLTech · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 3 captures on record
What the publisher says
As described on AWS Marketplace.
Software teams today face an ever-growing backlog of code reviews, security audits, and compliance checks. Manual code review is slow, inconsistent, and often misses critical security vulnerabilities or architectural anti-patterns. CodeSentinel is an Agentic AI intelligent code review platform that leverages Amazon Bedrock to automate the entire code review lifecycle--from code ingestion through dependency analysis, individual file review, and final report generation--in a single, orchestrated workflow.
Unlike traditional static analysis tools, CodeSentinel uses a multi-step agentic workflow with extended thinking capabilities, orchestrating code review through five steps:
Show the rest of the publisher’s description (13 more lines)
Step 1 - Load Code: Ingests source code from CodeCommit branches, CodeCommit PRs, S3 URIs, ZIP uploads, AWS Lambda functions, and Bedrock Agents. Supports .py, .js, .ts, .java, .go, .rb, .php, .c, .cpp, .h, .cs, .rs, .swift, .kt, .sh, .yaml, .yml, .json, .tf, and .sql files.
Step 2 - Build Dependency Graph: Parses import/require/from statements to build a file-to-file dependency graph. Performs topological sort for bottom-up review order, detects circular dependencies, identifies AWS services used per file, extracts environment variable references, and lists external libraries.
Step 3 - Review Files with Fix Recommendations: Reads each file in dependency order, passing a rolling summary of prior findings as context. Analyzes for Security (OWASP Top 10, hardcoded secrets, injection risks), AWS Well-Architected Framework (all 6 pillars), Bugs and Logic Errors, Code Quality, Performance, and Cross-File Issues. Each finding includes severity (CRITICAL/HIGH/MEDIUM/LOW/INFO), file name, approximate line number, category, issue description, impact, and fix recommendation.
Step 4 - Generate Report: Compiles all findings into a structured Markdown report with severity summary. Automatically exports the report and persists full metadata for historical tracking, trend analysis, and delta reviews.
Step 5 - Next Review: Loads the previous review's findings, takes the latest code version, and identifies which issues are fixed, which remain unresolved, and any new issues introduced.
Key Features:
- Multi-Source Code Ingestion from CodeCommit, S3, ZIP upload, AWS Lambda, and Bedrock Agent configurations
- Automatic Dependency Graph construction ensuring foundational modules are reviewed before dependents
- Six-Dimension Analysis covering Security, AWS Well-Architected, Bugs, Code Quality, Performance, and Cross-File Issues
- Severity-Ranked Findings with file name, line number, category, business impact, and fix recommendations
- Persistent Review History enabling trend analysis and audit trails
- Follow-Up Reviews that identify fixed, unresolved, and newly introduced issues
Target Audience: Software engineering teams, DevSecOps teams, cloud architects, and platform engineering teams at enterprises and ISVs who deploy workloads on AWS and need automated, consistent, and audit-ready code review at scale.
Highlights
Highlighted by the publisher on AWS Marketplace.
Multi-Source Agentic AI Workflow: CodeSentinel deploys a five-step agentic AI workflow built on Amazon Bedrock--ingesting code from CodeCommit, S3, ZIP, Lambda, and Bedrock Agents, building a dependency graph for correct review order, analyzing each file, generating a structured severity-ranked Markdown report, and cross-verifying code against previous versions--all without human intervention.
Deep Multi-Dimensional Analysis Across Security, AWS Well-Architected, and Code Quality: Unlike single-dimension linters or SAST tools, CodeSentinel performs simultaneous analysis across six dimensions: Security (OWASP Top 10, hardcoded secrets, injection risks), all six AWS Well-Architected Framework pillars, Bugs and Logic Errors, Code Quality, Performance, and Cross-File Issues.
Persistent Review History for Continuous Improvement: Every generated report and review dataset is persisted for cross-verifying the codebase against newer versions, enabling full audit trails and trend analysis. The Next Review feature performs follow-up reviews that explicitly identify fixed issues, unresolved issues, and newly introduced issues.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-07-01
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

