Securing AWS AgentCore Harness Credentials
🔒 Unit 42 researchers found that default AWS AgentCore Harness configurations can enable prompt-injection attacks that cause the harness to exfiltrate plaintext credentials from AgentCore Identity. The harness ships built-in tools, including a root-running shell enabled by default, which can access credentials when they are resolved to memory. AWS closed the report as informative under the shared responsibility model; operators should scope allowedTools, apply least privilege to identity vault accounts, and monitor egress from harness containers. Unit 42 offers cloud assessments and incident response support.
