AWS AgentCore Harness exposes credentials through agent tools
On September 18, Unit 42 said AWS AgentCore Harness in its default configuration could be steered by prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. The same research team had already flagged a different AgentCore credential path in April, which shows AWS keeps running into the same class of problem in different forms.
The harness’s built-in shell is enabled by default, runs as root, and reaches the same memory space where secrets are resolved into plaintext. Once an attacker gets the agent to run a command, that command inherits the agent’s privileges and can read whatever the agent itself can see.
That pushes the security boundary up to identity, memory, and tool scope rather than one prompt route. For teams using autonomous agents with shared tools and secret access, closing one injection path does not end the underlying exposure if the agent can still read and act with the same privileges.
'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
A now-patched vulnerablity in AWS Bedrock AgentCore could allow attackers to use one AI chatbot to take over an organization's entire fleet of AI agents.