Back to the registry
Agent passport

Agentic AI CodeSentinel-Code Review, Dependency & Security analysis

HCLTech · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 3 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Software teams today face an ever-growing backlog of code reviews, security audits, and compliance checks. Manual code review is slow, inconsistent, and often misses critical security vulnerabilities or architectural anti-patterns. CodeSentinel is an Agentic AI intelligent code review platform that leverages Amazon Bedrock to automate the entire code review lifecycle--from code ingestion through dependency analysis, individual file review, and final report generation--in a single, orchestrated workflow.

Unlike traditional static analysis tools, CodeSentinel uses a multi-step agentic workflow with extended thinking capabilities, orchestrating code review through five steps:

Show the rest of the publisher’s description (13 more lines)

Step 1 - Load Code: Ingests source code from CodeCommit branches, CodeCommit PRs, S3 URIs, ZIP uploads, AWS Lambda functions, and Bedrock Agents. Supports .py, .js, .ts, .java, .go, .rb, .php, .c, .cpp, .h, .cs, .rs, .swift, .kt, .sh, .yaml, .yml, .json, .tf, and .sql files.

Step 2 - Build Dependency Graph: Parses import/require/from statements to build a file-to-file dependency graph. Performs topological sort for bottom-up review order, detects circular dependencies, identifies AWS services used per file, extracts environment variable references, and lists external libraries.

Step 3 - Review Files with Fix Recommendations: Reads each file in dependency order, passing a rolling summary of prior findings as context. Analyzes for Security (OWASP Top 10, hardcoded secrets, injection risks), AWS Well-Architected Framework (all 6 pillars), Bugs and Logic Errors, Code Quality, Performance, and Cross-File Issues. Each finding includes severity (CRITICAL/HIGH/MEDIUM/LOW/INFO), file name, approximate line number, category, issue description, impact, and fix recommendation.

Step 4 - Generate Report: Compiles all findings into a structured Markdown report with severity summary. Automatically exports the report and persists full metadata for historical tracking, trend analysis, and delta reviews.

Step 5 - Next Review: Loads the previous review's findings, takes the latest code version, and identifies which issues are fixed, which remain unresolved, and any new issues introduced.

Key Features:

  • Multi-Source Code Ingestion from CodeCommit, S3, ZIP upload, AWS Lambda, and Bedrock Agent configurations
  • Automatic Dependency Graph construction ensuring foundational modules are reviewed before dependents
  • Six-Dimension Analysis covering Security, AWS Well-Architected, Bugs, Code Quality, Performance, and Cross-File Issues
  • Severity-Ranked Findings with file name, line number, category, business impact, and fix recommendations
  • Persistent Review History enabling trend analysis and audit trails
  • Follow-Up Reviews that identify fixed, unresolved, and newly introduced issues

Target Audience: Software engineering teams, DevSecOps teams, cloud architects, and platform engineering teams at enterprises and ISVs who deploy workloads on AWS and need automated, consistent, and audit-ready code review at scale.

Highlights

Highlighted by the publisher on AWS Marketplace.

Multi-Source Agentic AI Workflow: CodeSentinel deploys a five-step agentic AI workflow built on Amazon Bedrock--ingesting code from CodeCommit, S3, ZIP, Lambda, and Bedrock Agents, building a dependency graph for correct review order, analyzing each file, generating a structured severity-ranked Markdown report, and cross-verifying code against previous versions--all without human intervention.

Deep Multi-Dimensional Analysis Across Security, AWS Well-Architected, and Code Quality: Unlike single-dimension linters or SAST tools, CodeSentinel performs simultaneous analysis across six dimensions: Security (OWASP Top 10, hardcoded secrets, injection risks), all six AWS Well-Architected Framework pillars, Bugs and Logic Errors, Code Quality, Performance, and Cross-File Issues.

Persistent Review History for Continuous Improvement: Every generated report and review dataset is persisted for cross-verifying the codebase against newer versions, enabling full audit trails and trend analysis. The Next Review feature performs follow-up reviews that explicitly identify fixed issues, unresolved issues, and newly introduced issues.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-07-01

CompanyHCL Technologies LimitedAutomated
HQIndiaAutomated
IndustryTechnologyAutomated
Websitehttps://www.hcltech.com/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
For deployment assistance, technical support, and product inquiries, please contact the HCL Tech AWS Ecosystem team at awsecosystembu@hcltech.com.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.