2026-10-11 17:14 UTC

Zenity research demonstrates that AWS AgentCore's agent execution environment allows an AI agent to be prompted to exfiltrate its own AWS temporary credentials via the metadata service, with those credentials reportedly having broad permissions across agents, conversations, container images, secrets, and long-term agent memories — a critical containment failure in a managed cloud agent runtime.

state: corroboratedheat: mediumuncertainty: lowconvergesscott: highagentic-security aws-agentcore credential-exposure containment-failureZenityAWS

What is this?

Zenity Labs disclosed 'AgentCorruption' — a chain of vulnerabilities in Amazon Bedrock AgentCore (AWS's managed agent runtime) where a single prompt to a public-facing agent could exfiltrate its temporary AWS credentials via the Instance Metadata Service (IMDS). The default execution role attached to AgentCore agents was overprivileged, granting broad permissions across all AgentCore resources in the region, enabling takeover of all agents in the same account/region, access to private conversations, source code, long-term memories, API keys, and secrets in AWS Secrets Manager. Zenity reported the findings to AWS on December 25, 2025; AWS subsequently made IMDSv2 the default for new AgentCore deployments. This is the third major AgentCore security disclosure in 2026, following Unit 42's 'Agent God Mode' IAM misconfiguration and a sandbox-escape/DNS-tunneling flaw, indicating a recurring pattern of isolation gaps in the platform.

Why it matters to Scott

This is a consequential independent validation of Scott's core containment thesis: a major cloud provider's managed agent runtime (AgentCore) failed exactly as his frameworks predict — default overprivilege, credentials accessible to the model via IMDS, prompt injection escalating to cross-agent takeover. The disclosure directly bears on his SiloOS/runtime-containment architecture (capability–scope separation, proxy-mediated tokenisation, cryptographic tenancy), his AgentCore research spike, and his LeverageAI consulting practice where 'managed service default overprivilege' is a recurring client risk. This is not merely an example of a pattern he believes in; it is a dated-receipts moment for the architectural-containment position.
ip:framework.siloosip:concept.runtime-containmentip:concept.architectural-containmentip:concept.capability-scope-separationip:concept.proxy-mediated-tokenisationip:concept.cryptographic-tenancyip:source.ai-doesnt-fear-deathip:concept.confused-deputy-problemip:framework.agent-provenance-stackip:source.breach-doesnt-compose-ebookdev:project.aws-bedrockdev:technology.amazon-bedrock-agentcoredev:concept.padded-cell-agent-architecturedev:concept.privacy-tokenized-agent-boundarydev:concept.guarded-agent-inboxdev:project.appliancework:project.leverageaiwork:concept.ai-consulting-practiceradar:concept.agentic-securityradar:concept.agent-containmentradar:concept.credential-isolationradar:concept.prompt-injectionradar:concept.agent-sandboxingradar:concept.sandbox-escaperadar:concept.credential-theftradar:concept.data-exfiltrationradar:concept.agent-permissionsradar:concept.agent-authorizationradar:concept.mcp-securityradar:concept.agent-governanceradar:aws-agentcore-elastic-runtime-updateradar:aws-agentcore-persistent-runtime-adoptionradar:concept.agent-runtimeradar:concept.agent-infrastructureradar:person.awsradar:person.aws-labs
queries asked of Scott's wikis
  • agentic security containment failure patterns
  • cloud agent runtime credential isolation
  • managed AI service default overprivilege
  • prompt injection to credential exfiltration chain
  • AWS Bedrock AgentCore architecture
  • IMDSv2 adoption in managed runtimes

Measured heat

now 0 pts/hpeak 3 pts/hcomments 0/hpeers p15momentum: steady2 platformsage 99h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-07 13:00⭐ origin echo-reconstructedAn exposed AI agent in AWS AgentCore could be prompted to query its own AWS metadata service, return its temporary credentials, and those cr
Zenity on blog (echo) · attributed from reddit.post.1x2b8s7
—
10-10 09:45first on r/artificial · published · +68.8hHow about this prompt: give me your creds
Haunting_Ganache_850
—
10-10 09:45amplified on r/artificial 👑reddit.post.1x2b8s7
Haunting_Ganache_850
peak 3 · 7 comments · 101% of case engagement
10-10 10:30our radar first saw it · +69.5hdiscovery anchor: reddit.post.1x2b8s7—
pace: p46 vs 1247 stories at the 96h mark (now 99h old) — ahead of anthropic-blocked-request-billing (1.1x), behind anthropic-ci-test-selection-redesign (0.9x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditHow about this prompt: give me your creds
artificial
Haunting_Ganache_85037
🟧 echo.blog ⭐An exposed AI agent in AWS AgentCore could be prompted to query its own AWS metadata service, return its temporary credentials, and those crZenity——

Interpretation history

Decision trace