Skip to main content

AWS AgentCore Harness Default Settings Allow Credential Exfiltration

5 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Default AWS AgentCore Harness configurations risk plaintext credential exfiltration and root command execution.
  • Affected systems include AWS AgentCore Harness with default `shell` and `file_operations` tools enabled.
  • Remediation requires restricting `allowedTools` and implementing egress filtering for AgentCore sessions immediately.

Advertisement

Overview: Critical Vulnerability in AWS AgentCore Harness Defaults

Unit 42 researchers have identified a significant security concern within Amazon Web Services (AWS) AgentCore Harness, where default configurations could permit attackers to leverage prompt injection techniques. This method allows adversaries to steer an agent’s actions, potentially leading to the exfiltration of plaintext credentials managed by AgentCore Identity. The core issue lies with the harness’s built-in shell tool, enabled by default, which accesses the same memory space where sensitive credentials are resolved into an unencrypted format.

Technical Analysis: AWS AgentCore Harness Default Shell Security

The Unit 42 research highlights a critical interaction between AWS AgentCore Harness and its AgentCore Identity component. AgentCore Identity is designed to provide encryption at rest and in transit, leveraging Key Management Service (KMS) keys and IAM-gated access for credentials. However, the security posture changes at runtime when credentials must temporarily leave this secure “vault” to be used by an agent.

The vulnerability stems from two built-in tools, shell and file_operations, which are enabled by default in every AgentCore Harness session. These tools grant the agent the ability to execute bash commands and manage files, significantly enhancing its autonomy and productivity. The crucial finding is that the shell tool runs with root privileges inside the harness. This means that if an attacker successfully uses prompt injection to compel an agent to run a command, that command inherits full root access within the harness environment.

Compounding this, the shell tool’s execution environment directly interfaces with the memory space where AgentCore Identity resolves credentials into plaintext for operational use. An attacker, by inducing the agent to execute specific commands via the shell tool, could potentially dump or exfiltrate these sensitive credentials before they are re-encrypted or secured. This is not a result of misconfiguration by the user; rather, it is the out-of-the-box state of the AgentCore Harness unless explicit restrictions are applied. The ability for an agent to perform arbitrary shell commands and read/write files, even when not explicitly required by the session, creates a substantial attack surface. This mechanism illustrates how prompt injection, traditionally a concern for manipulating LLM outputs, can be weaponized to achieve system-level compromise in agents with privileged tooling.

The Role of Programmatic Tool Use

The evolution of AI agents has shifted from simple question-answering models to autonomous entities capable of complex, multi-step tasks. This capability relies heavily on programmatic tool use, where models orchestrate workflows by writing scripts rather than calling tools one-by-one. While highly efficient, this advancement also means agents are equipped with powerful interfaces like the shell tool, which can become a conduit for exploitation if not properly secured. The shell tool’s direct access and root privileges within the AgentCore Harness provide an avenue for attackers to bypass intended operational boundaries.

AWS Stance and Shared Responsibility

AWS acknowledged the Unit 42 findings but classified the report as “informative” under the AgentCore shared responsibility model. AWS emphasized that allowedTools scoping and egress filtering are customer-side controls. This stance implies that while the default configuration presents a risk, the ultimate responsibility for mitigating this specific threat falls to the customer to properly configure their AgentCore Harness instances. Security professionals must understand that “out-of-the-box” settings for advanced AI agent platforms may carry inherent risks that require immediate customer intervention to secure.

Actionable Recommendations: Mitigate AgentCore Harness Prompt Injection

Defending against this type of attack requires a layered approach, with a strong emphasis on configuration best practices. Organizations deploying AWS AgentCore Harness should prioritize the following actions to detect AWS AgentCore Harness credential exfiltration and prevent exploitation:

  • Strict allowedTools Scoping: The most critical immediate action is to restrict the allowedTools parameter for every AgentCore Harness session. Configure this parameter to include only the absolute minimum set of tools required for each specific agent’s function. By default, both shell and file_operations are enabled; disable them unless explicitly necessary and fully justified.
  • Implement Egress Filtering: Apply strict egress filtering at the network level for AgentCore Harness environments. This measure helps prevent exfiltration of sensitive data, even if an attacker successfully injects commands. Limit outbound connections to only necessary and approved endpoints.
  • Principle of Least Privilege: Ensure that the IAM roles assigned to AgentCore Harness agents adhere strictly to the principle of least privilege. Agents should only have permissions necessary to perform their designated tasks, minimizing the potential impact if a compromise occurs.
  • Continuous Monitoring: Implement comprehensive logging and monitoring for AgentCore Harness activities, paying close attention to unexpected shell commands, file operations, or unusual network traffic originating from agent sessions. Anomaly detection can help identify early signs of attempted prompt injection or credential access.
  • Regular Security Assessments: Conduct regular cloud security assessments to identify misconfigurations, security gaps, and adherence to best practices within your AWS environment, particularly for services like AgentCore Harness that involve autonomous agents and sensitive data.

By proactively addressing these configuration defaults and implementing a strong security posture, organizations can significantly reduce the risk of credential exfiltration and command execution via prompt injection in AWS AgentCore Harness environments.

Related: Cloud Security Index 2026: Multi-Cloud Risk Analysis, Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data

Advertisement

Advertisement