Identity & Access · Credential Theft

AgentCore Harness Shell Leaks Vaulted Credentials

Unit 42 found that Amazon Bedrock AgentCore Harness’s default-enabled built-in shell can be abused through prompt injection to exfiltrate plaintext credentials from AgentCore Identity. AWS reviewed the report and closed it as informative under its shared responsibility model.

The issue is runtime, not storage: AgentCore Identity may keep secrets encrypted and IAM-guarded in the vault, but the harness has to resolve them into plaintext to use them. Unit 42 showed the shell tool can reach that same working memory, so a malicious prompt can turn the agent itself into the path that leaks the secret.

For teams running Harness agents with downstream MCP or other tool integrations, the exposure sits wherever an agent can both load a secret and act on it. Vault controls still matter, but they do not by themselves stop credential theft once the agent runtime is the place secrets become usable.

1 source · 3 days ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: AgentCore Harness Shell Leaks Vaulted Credentials