Skip to main content

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

0
High
Analysiscloudai
Published: 09/18/2026 (09/18/2026, 10:00:36 UTC)
Source: Palo Alto Unit 42

Description

Unit 42 researchers identified that AWS AgentCore Harness's default configuration enables a built-in shell tool with root privileges, which can be exploited via prompt injection to exfiltrate plaintext credentials from the AgentCore Identity vault. The shell tool is enabled by default and can execute arbitrary shell commands with root access, posing a risk if allowedTools is not scoped properly. AWS reviewed the finding and classified it as informative under the shared responsibility model, emphasizing customer-side controls such as scoping allowedTools and egress filtering. Mitigation involves restricting allowedTools to only necessary tools, applying least privilege to identity vault service accounts, and monitoring outbound traffic from harness containers. No official patch or fix is indicated; remediation relies on configuration and operational controls.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 10:10:41 UTC

Technical Analysis

The AWS AgentCore Harness is a managed runtime for AI agents that includes built-in tools enabled by default, notably a shell tool that executes bash commands as root. Researchers found that this default configuration allows attackers to perform prompt injection attacks that cause the agent to run arbitrary shell commands, accessing plaintext credentials stored in the AgentCore Identity vault. The vault provides encryption and IAM controls, but at runtime, credentials must be resolved to plaintext in memory, which the shell tool can access. AWS reviewed the report and closed it as informative, citing that allowedTools scoping and egress filtering are customer responsibilities under the shared responsibility model. Operators are advised to restrict allowedTools, apply least privilege to service accounts, and monitor outbound traffic to mitigate risks.

Potential Impact

If the default configuration is used without restricting allowedTools, an attacker can leverage prompt injection to execute arbitrary shell commands with root privileges inside the AgentCore Harness. This can lead to exfiltration of plaintext credentials managed by the AgentCore Identity vault. The impact includes unauthorized access to sensitive credentials and potential compromise of downstream services authenticated by those credentials. However, AWS considers this a customer-side configuration issue rather than a vulnerability in the service itself.

Defensive Guidance

AWS has not issued a patch or official fix; remediation depends on customer configuration. Operators should scope the allowedTools parameter to only the tools necessary for each session, disabling the default shell tool if not required. Identity vault service accounts should be assigned least privilege access tailored to downstream integrations. Additionally, monitoring and filtering outbound traffic from harness containers can help detect and prevent credential exfiltration. These layered defenses align with AWS's shared responsibility model for AgentCore Harness security.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","fetched":true,"fetchedAt":"2026-09-18T10:10:37.489Z","wordCount":4762}

Threat ID: 6aad0e1d55bf5e2cf5dca60e

Added to database: 09/18/2026, 10:10:37 UTC

Last enriched: 09/18/2026, 10:10:41 UTC

Last updated: 09/18/2026, 11:09:36 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses