Identity · 3 days ago
Unit 42 found that Amazon Bedrock AgentCore Harness’s default-enabled built-in shell can be abused through prompt injection to exfiltrate plaintext credentials from AgentCore Identity. AWS reviewed the report and closed it as informative under its shared responsibility model.
The issue is runtime, not storage: AgentCore Identity may keep secrets encrypted and IAM-guarded in the vault, but the harness has to resolve them into plaintext to use them. Unit 42 showed the shell tool can reach that same working memory, so a malicious prompt can turn the agent itself into the path that leaks the secret.
For teams running Harness agents with downstream MCP or other tool integrations, the exposure sits wherever an agent can both load a secret and act on it. Vault controls still matter, but they do not by themselves stop credential theft once the agent runtime is the place secrets become usable.
1 source covering this story
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.
Part of the PlainSec briefing for 2026-09-21