Zenity research demonstrates that AWS AgentCore's agent execution environment allows an AI agent to be prompted to exfiltrate its own AWS temporary credentials via the metadata service, with those credentials reportedly having broad permissions across agents, conversations, container images, secrets, and long-term agent memories — a critical containment failure in a managed cloud agent runtime.
state: corroboratedheat: mediumuncertainty: lowconvergesscott: highagentic-security aws-agentcore credential-exposure containment-failureZenityAWS
What is this?
Zenity Labs disclosed 'AgentCorruption' — a chain of vulnerabilities in Amazon Bedrock AgentCore (AWS's managed agent runtime) where a single prompt to a public-facing agent could exfiltrate its temporary AWS credentials via the Instance Metadata Service (IMDS). The default execution role attached to AgentCore agents was overprivileged, granting broad permissions across all AgentCore resources in the region, enabling takeover of all agents in the same account/region, access to private conversations, source code, long-term memories, API keys, and secrets in AWS Secrets Manager. Zenity reported the findings to AWS on December 25, 2025; AWS subsequently made IMDSv2 the default for new AgentCore deployments. This is the third major AgentCore security disclosure in 2026, following Unit 42's 'Agent God Mode' IAM misconfiguration and a sandbox-escape/DNS-tunneling flaw, indicating a recurring pattern of isolation gaps in the platform.
Why it matters to Scott
This is a consequential independent validation of Scott's core containment thesis: a major cloud provider's managed agent runtime (AgentCore) failed exactly as his frameworks predict — default overprivilege, credentials accessible to the model via IMDS, prompt injection escalating to cross-agent takeover. The disclosure directly bears on his SiloOS/runtime-containment architecture (capability–scope separation, proxy-mediated tokenisation, cryptographic tenancy), his AgentCore research spike, and his LeverageAI consulting practice where 'managed service default overprivilege' is a recurring client risk. This is not merely an example of a pattern he believes in; it is a dated-receipts moment for the architectural-containment position.
ip:framework.siloosip:concept.runtime-containmentip:concept.architectural-containmentip:concept.capability-scope-separationip:concept.proxy-mediated-tokenisationip:concept.cryptographic-tenancyip:source.ai-doesnt-fear-deathip:concept.confused-deputy-problemip:framework.agent-provenance-stackip:source.breach-doesnt-compose-ebookdev:project.aws-bedrockdev:technology.amazon-bedrock-agentcoredev:concept.padded-cell-agent-architecturedev:concept.privacy-tokenized-agent-boundarydev:concept.guarded-agent-inboxdev:project.appliancework:project.leverageaiwork:concept.ai-consulting-practiceradar:concept.agentic-securityradar:concept.agent-containmentradar:concept.credential-isolationradar:concept.prompt-injectionradar:concept.agent-sandboxingradar:concept.sandbox-escaperadar:concept.credential-theftradar:concept.data-exfiltrationradar:concept.agent-permissionsradar:concept.agent-authorizationradar:concept.mcp-securityradar:concept.agent-governanceradar:aws-agentcore-elastic-runtime-updateradar:aws-agentcore-persistent-runtime-adoptionradar:concept.agent-runtimeradar:concept.agent-infrastructureradar:person.awsradar:person.aws-labs
queries asked of Scott's wikis
- agentic security containment failure patterns
- cloud agent runtime credential isolation
- managed AI service default overprivilege
- prompt injection to credential exfiltration chain
- AWS Bedrock AgentCore architecture
- IMDSv2 adoption in managed runtimes
Measured heat
now 0 pts/hpeak 3 pts/hcomments 0/hpeers p15momentum: steady2 platformsage 99h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p46 vs 1247 stories at the 96h mark (now 99h old) — ahead of anthropic-blocked-request-billing (1.1x), behind anthropic-ci-test-selection-redesign (0.9x)
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-10-11T04:40:22Z
Case promoted to corroborated: Zenity's first-party research demonstrates a concrete credential-exfiltration chain in AWS AgentCore; AWS has responded by making IMDSv2 default for new deployments, confirming the finding. This is the third major AgentCore isolation failure disclosed in 2026 (following Unit 42's 'Agent God Mode' and a sandbox-escape/DNS-tunneling flaw), establishing a pattern of default overprivilege in the platform. Scott's up-vote signals direct relevance to his containment frameworks and consulting practice.
2026-10-10T10:41:47Z
grounded: converges/high — This is a consequential independent validation of Scott's core containment thesis: a major cloud provider's managed agent runtime (AgentCore) failed exactly as
2026-10-10T10:34:27Z
case created — First-party security research discloses a concrete credential-exfiltration chain in AWS's managed agent runtime, establishing a developing episode about cloud agent containment failure.
Decision trace
- 10-11 15:40repriceCase promoted to corroborated: Zenity's first-party research demonstrates a concrete credential-exfiltration chain in AWS AgentCore; AWS has responded by making IMDSv2 default for new deployments
- 10-11 15:00feedback_interruptScott vote via UI
- 10-11 10:03attention_communicatedZenity research demonstrates an AI agent in AWS AgentCore can be prompted to query the instance metadata service (IMDS) and return its temporary AWS credentials. Those credentials reportedly had permi
- 10-11 10:03attention_routeFirst independent security research disclosing a concrete credential-exfiltration chain in a major cloud provider's managed agent runtime, confirming Scott's containment frameworks with a da
- 10-10 22:32sensor_dirtycomment_update
- 10-10 22:07attention_routeFirst independent security research disclosing a concrete credential-exfiltration chain in a major cloud provider's managed agent runtime, confirming Scott's containment frameworks with a da
- 10-10 21:56attention_routeFirst independent security research disclosing a concrete credential-exfiltration chain in a major cloud provider's managed agent runtime, confirming Scott's containment frameworks with a da
- 10-10 21:53attention_candidatecreate
- 10-10 21:41groundThis is a consequential independent validation of Scott's core containment thesis: a major cloud provider's managed agent runtime (AgentCore) failed exactly as his frameworks predict — defau
- 10-10 21:34createFirst-party security research discloses a concrete credential-exfiltration chain in AWS's managed agent runtime, establishing a developing episode about cloud agent containment failure.