# AWS AgentCore Harness Default Settings Allow Credential Exfiltration

> Attackers can exploit default AWS AgentCore Harness settings via prompt injection to exfiltrate plaintext credentials and execute commands as root.

- Published: 2026-10-01T15:05:45.000Z
- Severity: high
- Category: Vulnerabilities
- Tags: Prompt Injection, Cloud Security, Misconfiguration, AWS AgentCore Harness, Credential Exfiltration
- Author: Runtime Rebel Intel
- Primary source: https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
- Canonical: https://runtimerebel.com/blog/aws-agentcore-harness-default-settings-allow-credential-exfiltration

## Key points

- Default AWS AgentCore Harness configurations risk plaintext credential exfiltration and root command execution.
- Affected systems include AWS AgentCore Harness with default `shell` and `file_operations` tools enabled.
- Remediation requires restricting `allowedTools` and implementing egress filtering for AgentCore sessions immediately.

## Overview: Critical [Vulnerability](/glossary#vulnerability) in AWS AgentCore Harness Defaults

Unit 42 researchers have identified a significant security concern within Amazon Web Services (AWS) AgentCore Harness, where default configurations could permit attackers to leverage [prompt injection](/glossary#prompt-injection) techniques. This method allows adversaries to steer an agent's actions, potentially leading to the exfiltration of plaintext credentials managed by AgentCore Identity. The core issue lies with the harness's built-in `shell` tool, enabled by default, which accesses the same memory space where sensitive credentials are resolved into an unencrypted format.

## Technical Analysis: AWS AgentCore Harness Default Shell Security

The [Unit 42](https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/) research highlights a critical interaction between AWS AgentCore Harness and its AgentCore Identity component. AgentCore Identity is designed to provide [encryption](/glossary#encryption) at rest and in transit, leveraging [Key Management](/glossary#key-management) Service (KMS) keys and [IAM](/glossary#iam)-gated access for credentials. However, the security posture changes at runtime when credentials must temporarily leave this secure "vault" to be used by an agent.

The vulnerability stems from two built-in tools, `shell` and `file_operations`, which are enabled by default in every AgentCore Harness session. These tools grant the agent the ability to execute `bash` commands and manage files, significantly enhancing its autonomy and productivity. The crucial finding is that the `shell` tool runs with `root` privileges inside the harness. This means that if an attacker successfully uses prompt injection to compel an agent to run a command, that command inherits full `root` access within the harness environment.

Compounding this, the `shell` tool's execution environment directly interfaces with the memory space where AgentCore Identity resolves credentials into plaintext for operational use. An attacker, by inducing the agent to execute specific commands via the `shell` tool, could potentially dump or exfiltrate these sensitive credentials before they are re-encrypted or secured. This is not a result of misconfiguration by the user; rather, it is the out-of-the-box state of the AgentCore Harness unless explicit restrictions are applied. The ability for an agent to perform arbitrary shell commands and read/write files, even when not explicitly required by the session, creates a substantial [attack surface](/glossary#attack-surface). This mechanism illustrates how prompt injection, traditionally a concern for manipulating [LLM](/glossary#jailbreak-llm) outputs, can be weaponized to achieve system-level compromise in agents with privileged tooling.

### The Role of Programmatic Tool Use

The evolution of [AI](/glossary#ai) agents has shifted from simple question-answering models to autonomous entities capable of complex, multi-step tasks. This capability relies heavily on programmatic tool use, where models orchestrate workflows by writing scripts rather than calling tools one-by-one. While highly efficient, this advancement also means agents are equipped with powerful interfaces like the `shell` tool, which can become a conduit for exploitation if not properly secured. The `shell` tool's direct access and `root` privileges within the AgentCore Harness provide an avenue for attackers to bypass intended operational boundaries.

## AWS Stance and Shared Responsibility

AWS acknowledged the Unit 42 findings but classified the report as "informative" under the AgentCore shared responsibility model. AWS emphasized that `allowedTools` scoping and [egress filtering](/glossary#egress-filtering) are customer-side controls. This stance implies that while the default configuration presents a risk, the ultimate responsibility for mitigating this specific threat falls to the customer to properly configure their AgentCore Harness instances. Security professionals must understand that "out-of-the-box" settings for advanced [AI agent](/glossary#ai-agent) platforms may carry inherent risks that require immediate customer intervention to secure.

## Actionable Recommendations: Mitigate AgentCore Harness Prompt Injection

Defending against this type of attack requires a layered approach, with a strong emphasis on configuration best practices. Organizations deploying AWS AgentCore Harness should prioritize the following actions to detect AWS AgentCore Harness credential exfiltration and prevent exploitation:

*   **Strict `allowedTools` Scoping:** The most critical immediate action is to restrict the `allowedTools` parameter for every AgentCore Harness session. Configure this parameter to include only the absolute minimum set of tools required for each specific agent's function. By default, both `shell` and `file_operations` are enabled; disable them unless explicitly necessary and fully justified.
*   **Implement Egress Filtering:** Apply strict egress filtering at the network level for AgentCore Harness environments. This measure helps prevent exfiltration of sensitive data, even if an attacker successfully injects commands. Limit outbound connections to only necessary and approved endpoints.
*   **Principle of [Least Privilege](/glossary#least-privilege):** Ensure that the IAM roles assigned to AgentCore Harness agents adhere strictly to the principle of least privilege. Agents should only have permissions necessary to perform their designated tasks, minimizing the potential impact if a compromise occurs.
*   **Continuous Monitoring:** Implement comprehensive logging and monitoring for AgentCore Harness activities, paying close attention to unexpected `shell` commands, file operations, or unusual network traffic originating from agent sessions. Anomaly detection can help identify early signs of attempted prompt injection or credential access.
*   **Regular Security Assessments:** Conduct regular [cloud security](/glossary#cloud-security) assessments to identify misconfigurations, security gaps, and adherence to best practices within your AWS environment, particularly for services like AgentCore Harness that involve autonomous agents and sensitive data.

By proactively addressing these configuration defaults and implementing a strong security posture, organizations can significantly reduce the risk of credential exfiltration and command execution via prompt injection in AWS AgentCore Harness environments.

**Related:** [Cloud Security Index 2026: Multi-Cloud Risk Analysis](/blog/cloud-security-index-2026-multi-cloud-risk-analysis), [Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data](/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/aws-agentcore-harness-default-settings-allow-credential-exfiltration
