On October 7, 2026, Amazon Web Services (AWS) published a guide on configuring AI models with steering files to perform structured security vulnerability triage.
What it does
AWS explains that a steering file encodes a security team's triage methodology as machine-executable instructions loaded by AI coding assistants at the start of every session to ensure consistency.
Before you start
AWS states that different tools use different conventions, such as Kiro reading markdown files from a .kiro/steering/ directory, Claude Code using CLAUDE.md, Cursor using .cursorrules, and GitHub Copilot using .github/copilot-instructions.md.
Steps
Step 1: To use as a Kiro steering file, AWS states you can drop the steering file into your repository at .kiro/steering/vuln-triage.md, place it in ~/.kiro/steering/ to apply it across every workspace, or add it to a custom agent's resources explicitly.
Step 2: To use as a Kiro skill, AWS says you place it as a folder containing a SKILL.md file in .kiro/skills/vuln-triage/ or ~/.kiro/skills/ for on-demand use, matching the folder name to the skill name.
Step 3: To adapt for other tools, AWS states the repository ships the same content as a CLAUDE.md file for Claude Code, and principles apply to any assistant that loads persistent instructions.
What the company says
AWS said that the steering file "encodes the architectural principles from the harness post as operational instructions" and changes default model behavior to enforce structural verification and evidence-based scoring.
What to do
- Drop the steering file into your repository at .kiro/steering/vuln-triage.md or place it in ~/.kiro/steering/ to apply the methodology across every workspace.
- Place the skill as a folder containing a SKILL.md file in .kiro/skills/vuln-triage/ or ~/.kiro/skills/ to make it available on demand.
- Consult your tool’s documentation for the filename and location it expects if adapting the content for other assistants like Claude Code.
Key facts and where they come from
- AWS released a steering file to encode architectural principles as operational instructions for AI models.
The steering file we’re releasing encodes the architectural principles from the harness post as operational instructions.
- Different AI coding assistant tools use varying conventions for storing persistent instruction files.
Different tools use different conventions—Kiro reads markdown files from a .kiro/steering/ directory, Claude Code uses CLAUDE.md, Cursor uses .cursorrules, and GitHub Copilot uses .github/copilot-instructions.md
