{"title":"AgentCore’s MMDSv2 Requirement Leaves Existing Sessions Unaffected","description":"The sampled records distinguish invocation-time metadata enforcement from generated IAM policy changes. They establish configuration requirements and narrower toolkit templates, but not automatic migration of previously created customer roles.","dataset_id":"spd:agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d","canonical_url":"https://superpowerdaily.com/research/agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d","version_url":"https://superpowerdaily.com/research/agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d","version":"Live","snapshot_hash":null,"date_created":null,"date_modified":"2026-10-09T04:17:35.713Z","license":{"name":"Superpower Daily data reuse terms","url":"https://superpowerdaily.com/terms"},"license_url":"https://superpowerdaily.com/terms","coverage_note":"The evidence_matrix supports a deployment-cohort checklist, not a vulnerability prevalence estimate. New-deployment metadata behavior is established only as an AWS statement reproduced by Zenity. Existing runtime invocation requirements and the existing-session exception are documented by AWS. Toolkit policy changes are identifiable in source, while migration of previously created roles remains unresolved in this sample. AWS’s explicit no-automatic-migration statement for agents created before October 13, 2025 concerns workload identity only and must remain separate from the metadata and execution-role remediation audit.","measurement_technique":["Synthesize the saved evidence without new collection or execution, preserving the original cutoff of October 9, 2026, 02:31 UTC and collection-context timestamp 2026-10-09T02:31:40.230Z.","Use the bounded sample of Zenity’s disclosure, AWS metadata, permissions and identity documentation, toolkit pull request 554, and the v0.3.10 and v0.3.14 execution-role templates.","Build an evidence_matrix separating new deployments, existing runtime invocations, existing sessions, newly generated toolkit policies and previously created customer roles. Record source, creation path, applicability, documented customer action and unresolved coverage for each row.","Classify documentary applicability as established, customer-action-dependent or unresolved. An established requirement is not proof that a customer deployment complies with it.","Compare conditional template branches rather than infer deployed account policies: runtime/* becomes runtime/agent_name-*, memory/* becomes memory/agent_name_mem-*, and the newer template omits the older conditional CreateMemory grant.","Keep chronology and creation paths separate: Zenity attributes February 14 metadata changes to AWS correspondence; toolkit hardening merged July 27; Zenity observed role restrictions September 29. Do not assume these describe the same rollout."],"methodology":["Synthesize the saved evidence without new collection or execution, preserving the original cutoff of October 9, 2026, 02:31 UTC and collection-context timestamp 2026-10-09T02:31:40.230Z.","Use the bounded sample of Zenity’s disclosure, AWS metadata, permissions and identity documentation, toolkit pull request 554, and the v0.3.10 and v0.3.14 execution-role templates.","Build an evidence_matrix separating new deployments, existing runtime invocations, existing sessions, newly generated toolkit policies and previously created customer roles. Record source, creation path, applicability, documented customer action and unresolved coverage for each row.","Classify documentary applicability as established, customer-action-dependent or unresolved. An established requirement is not proof that a customer deployment complies with it.","Compare conditional template branches rather than infer deployed account policies: runtime/* becomes runtime/agent_name-*, memory/* becomes memory/agent_name_mem-*, and the newer template omits the older conditional CreateMemory grant.","Keep chronology and creation paths separate: Zenity attributes February 14 metadata changes to AWS correspondence; toolkit hardening merged July 27; Zenity observed role restrictions September 29. Do not assume these describe the same rollout."],"metrics":[{"label":"Verified observations","value":"0","detail":"0 measured fields"},{"label":"Supported claims","value":"6","detail":"6 material findings"},{"label":"Cited sources","value":"7","detail":"7 primary or authoritative"},{"label":"Research score","value":"80","detail":"Automated topic and evidence score"}],"columns":[{"key":"entity","label":"Entity"},{"key":"metric","label":"Metric"},{"key":"value","label":"Value"},{"key":"unit","label":"Unit"},{"key":"observed","label":"Observed"},{"key":"source","label":"Source"},{"key":"transform","label":"Transform"}],"data":[],"sources":[{"name":"AWS","title":"docs.aws.amazon.com","url":"https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/service-linked-roles.html","records":0},{"name":"AWS","title":"docs.aws.amazon.com","url":"https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-security-best-practices.html","records":0},{"name":"AWS","title":"docs.aws.amazon.com","url":"https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-permissions.html","records":0},{"name":"AWS GitHub repository","title":"fix: update execution role policies for runtime, gateway, and evaluation by tynobleamazon · Pull Request #554 · aws/bedrock-agentcore-starter-toolkit","url":"https://github.com/aws/bedrock-agentcore-starter-toolkit/pull/554","records":0},{"name":"AWS GitHub repository","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/aws/bedrock-agentcore-starter-toolkit/v0.3.10/src/bedrock_agentcore_starter_toolkit/utils/runtime/templates/execution_role_policy.json.j2","records":0},{"name":"AWS GitHub repository","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/aws/bedrock-agentcore-starter-toolkit/v0.3.14/src/bedrock_agentcore_starter_toolkit/utils/runtime/templates/execution_role_policy.json.j2","records":0},{"name":"Zenity Labs","title":"Security Research | AgentCorruption: How A Single Prompt Collapsed The Entire Cloud Security Model | Zenity Labs","url":"https://labs.zenity.io/post/agentcorruption-how-a-single-prompt-collapsed-the-entire-cloud-security-model","records":0}],"provenance":{"publisher":"Superpower Daily","source_count":7,"source_urls":["https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/service-linked-roles.html","https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-security-best-practices.html","https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-permissions.html","https://github.com/aws/bedrock-agentcore-starter-toolkit/pull/554","https://raw.githubusercontent.com/aws/bedrock-agentcore-starter-toolkit/v0.3.10/src/bedrock_agentcore_starter_toolkit/utils/runtime/templates/execution_role_policy.json.j2","https://raw.githubusercontent.com/aws/bedrock-agentcore-starter-toolkit/v0.3.14/src/bedrock_agentcore_starter_toolkit/utils/runtime/templates/execution_role_policy.json.j2","https://labs.zenity.io/post/agentcorruption-how-a-single-prompt-collapsed-the-entire-cloud-security-model"],"methodology":["Synthesize the saved evidence without new collection or execution, preserving the original cutoff of October 9, 2026, 02:31 UTC and collection-context timestamp 2026-10-09T02:31:40.230Z.","Use the bounded sample of Zenity’s disclosure, AWS metadata, permissions and identity documentation, toolkit pull request 554, and the v0.3.10 and v0.3.14 execution-role templates.","Build an evidence_matrix separating new deployments, existing runtime invocations, existing sessions, newly generated toolkit policies and previously created customer roles. Record source, creation path, applicability, documented customer action and unresolved coverage for each row.","Classify documentary applicability as established, customer-action-dependent or unresolved. An established requirement is not proof that a customer deployment complies with it.","Compare conditional template branches rather than infer deployed account policies: runtime/* becomes runtime/agent_name-*, memory/* becomes memory/agent_name_mem-*, and the newer template omits the older conditional CreateMemory grant.","Keep chronology and creation paths separate: Zenity attributes February 14 metadata changes to AWS correspondence; toolkit hardening merged July 27; Zenity observed role restrictions September 29. Do not assume these describe the same rollout."],"snapshot_hash":null},"distributions":{"csv":"https://superpowerdaily.com/api/research/agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d?format=csv","json":"https://superpowerdaily.com/api/research/agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d?format=json"}}