A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Imported from official source

Cybersecurity Classified by Officially

Unit 42 researchers have identified an issue where using default configurations in Amazon Web Services (AWS) AgentCore Harness could allow attackers to steer an agent's actions through prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity.

To reach that finding, we examined two of the harness's many integrations:

  • AWS AgentCore Identity, the platform's recommended way to manage agent identities and store credentials (i.e. an identity vault)
  • A downstream Model Context Protocol (MCP) server, which the harness authenticates against using a credential from that identity vault
  • AWS AgentCore Identity provides encryption at rest, encryption in transit, key management service (KMS) keys and identity and access management (IAM)-gated access. We wanted to know what happens at runtime, when a credential has to leave the vault to be used. What we found was that the harness's own built-in shell tool, which is enabled by default, reaches into the same memory space where credentials are resolved to plaintext.

    We disclosed this finding to AWS. AWS reviewed and closed the report as informative under the AgentCore shared responsibility model, citing allowedTools scoping and egress filtering as customer-side controls.

    For operators building on AgentCore today, defense takes a layered approach:

  • Scope the allowedTools the harness can use to what it needs
  • Scope Identity vault service accounts to least privilege for the downstream integration
  • Watch outbound traffic from your harness containers
  • Palo Alto Networks customers are better protected from the threats discussed in this article through the following products and services:

    Unit 42 Cloud Security Assessment is an evaluation service that reviews cloud infrastructure to identify misconfigurations and security gaps.

    If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/

    Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Palo Alto Networks Unit 42 — imported from official source
    Official source
    https://unit42.paloaltonetworks.com/feed/ RSS
    Imported
    September 18, 2026 11:34
    Versions
    1 recorded
    Identity
    https://unit42.paloaltonetworks.com/?p=187347

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.