Vulnerabilities & Exploits · AI-Powered Attack

AWS AgentCore Harness exposes credentials through agent tools

On September 18, Unit 42 said AWS AgentCore Harness in its default configuration could be steered by prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. The same research team had already flagged a different AgentCore credential path in April, which shows AWS keeps running into the same class of problem in different forms.

The harness’s built-in shell is enabled by default, runs as root, and reaches the same memory space where secrets are resolved into plaintext. Once an attacker gets the agent to run a command, that command inherits the agent’s privileges and can read whatever the agent itself can see.

That pushes the security boundary up to identity, memory, and tool scope rather than one prompt route. For teams using autonomous agents with shared tools and secret access, closing one injection path does not end the underlying exposure if the agent can still read and act with the same privileges.

2 sources · Oct 8

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: AWS AgentCore Harness exposes credentials through agent tools

More from today