AWS ships Strands Box amid patched AgentCore flaws
AWS released Strands Box to constrain AI agents as researchers described a now-patched AgentCore flaw one prompt could use to seize a fleet.
On October 7, 2026, Amazon Web Services released Strands Box, an Apache 2.0 open-source developer-preview sandbox meant to stop autonomous AI agents from acting without enforceable limits. It pairs OS-level isolation with Dogwood — a history-aware policy engine in The Register’s account and an AWS policy language in CSO Online’s — checking shell, Python, API, tool, and MCP-broker activity against earlier actions, with rules enforced outside the agent so it cannot talk its way around them. Policies can limit Slack posts, Git pushes, and costly API calls, and CSO Online says a network gateway can approve outbound requests and attach credentials without exposing secrets. Sources disagree on both reach and platforms: The Register says the shell and Python interpreters expose actions so rules are not prompt-based, and that GitHub support is macOS now with Linux in development and a Windows client planned, while CSO Online says those interpreters run outside the sandbox, harness file tools skip Dogwood, and the preview runs only on Apple silicon Macs with macOS 15 or later, with undated ports planned for Bedrock AgentCore, ECS, and Kubernetes. Separately, Zenity Labs and Palo Alto Networks Unit 42 described recurring AgentCore failures, including AgentCorruption, which Zenity reported on December 25, 2025: one chat prompt against a public agent extracted temporary AWS credentials from the instance metadata service, and the live STS keys worked outside the platform against every agent sharing the default execution role in the same account and region. Dark Reading calls that flaw now patched, with no CVE and no confirmed exploitation, while CSO Online says Zenity’s specific path was fixed as of October 8 even as Unit 42’s September 2026 root-shell credential leak — closed by AWS as informative — and an earlier metadata-service gap show researchers arguing that other paths remained.
- On October 7, 2026, AWS released Strands Box, an Apache 2.0 open-source developer-preview sandbox that pairs OS isolation with Dogwood policies enforced outside the agent.
- Platform scope differs: The Register says GitHub support is macOS now, with Linux in development and a Windows client planned but undated; CSO Online says it runs only on Apple silicon Macs with macOS 15 or later, with undated ports eyed…
- Enforcement coverage differs: The Register says shell and Python interpreters expose actions so rules are not prompt-based; CSO Online says those interpreters run outside the sandbox and harness file tools skip Dogwood.
- Dogwood can limit Slack posts, Git pushes, and costly API calls; a network gateway can approve outbound requests and attach credentials without showing secrets to the agent.
- Zenity Labs reported on December 25, 2025 an AgentCorruption chain in Amazon Bedrock AgentCore: one chat prompt to a public agent obtained temporary AWS credentials from the instance metadata service.
- Those live STS keys worked outside AgentCore, and the default execution role applied to every agent in the same account and region, enabling image pulls, private-chat access, memory poisoning, secret retrieval, peer invocation, and…
- AWS later made IMDSv2 the default for new deployments and, around August 2026, narrowed the default role; Dark Reading calls AgentCorruption now patched, with no CVE and no confirmed in-the-wild exploitation.
- In September 2026, Unit 42 said default Harness settings let prompt injection use a built-in root shell to exfiltrate plaintext AgentCore Identity credentials, a report AWS closed as informative; an earlier microVM metadata flaw lacked…
Coverage timelineoldest first · each row is one article
- · 1d agoAWS launches open-source AI agent sandbox to prevent YOLO mode disasters
The Register · Security· 52
AWS open-sourced Strands Box, a sandbox that enforces deterministic policies on autonomous AI agents.
- · 14h agoAWS takes aim at runaway AI agent behavior with Strands Box
CSO Online· 47
AWS released Strands Box, an open-source macOS sandbox that enforces behavioral policies on AI agents.
- · 11h ago