A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Unit 42 found AWS AgentCore's default shell tool lets prompt injection reach plaintext AgentCore Identity credentials; AWS closed the report as informative.
Unit 42 found that AWS AgentCore Harness's default-enabled shell tool runs as root and shares the memory space where AgentCore Identity vault credentials resolve to plaintext, so prompt injection could steer an agent to exfiltrate credentials used for downstream MCP integrations. AWS closed the disclosure as informative under the AgentCore shared responsibility model, citing customer-side controls. Recommended defenses include scoping allowedTools, least-privilege vault service accounts, and monitoring outbound traffic from harness containers.