AgentCore Starter Toolkit Grants Broad IAM God Mode
🔐 Unit 42 found the AgentCore starter toolkit auto-creates overly permissive IAM roles that grant wildcard access to Bedrock AgentCore and ECR resources. The default deployment enables an “Agent God Mode” scenario where a compromised agent can exfiltrate container images, retrieve other agents’ MemoryIDs, invoke code interpreters, and read or poison memories across an entire AWS account. AWS updated documentation to warn these roles are intended for development; Unit 42 recommends creating scoped, least-privilege roles and auditing ECR, memory, and invoke permissions.
