AWS AgentCore prompt injection exposes credential risks
Palo Alto Networks’ Unit 42 researchers have demonstrated how an indirect prompt-injection attack against AWS’ AgentCore Harness could be used to extract plaintext credentials managed by AgentCore Identity.
The researchers said the attack worked with a default Harness configuration, combining malicious instructions embedded in external content with its built-in shell tool. AWS reviewed the disclosure and closed it as informational under the AgentCore shared-responsibility model, according to Unit 42.
Amazon Bedrock AgentCore provides infrastructure for deploying and operating AI agents. AgentCore Harness is built on AgentCore Runtime and provides agents with access to capabilities including tools, memory, identity, networking, and external services.
AWS documentation states that the Harness includes shell and file_operations as default tools. The shell can execute Bash commands, while file operations allow agents to view, create, and edit files. Both remain available unless developers restrict them using the allowedTools setting.
How the attack worked
Unit 42 tested...
Copyright of this story solely belongs to www.cloudcomputing-news.net. To see the full text click HERE