Zenity finds AWS agent flaws that let one chat prompt expose other agents
The AgentCorruption research links stolen temporary credentials to private conversations, poisoned memories and stored secrets. Zenity says AWS has since restricted the default permissions behind the attack.
Zenity’s AgentCorruption research shows the risk extended beyond prompt injection: credentials obtained through an agent’s web-request tool inherited a regional default execution role that could reach other AgentCore agents, read private conversations, and alter long-term memories. AWS said newly deployed agents had used IMDSv2 since February 14, 2026, addressing the credential-access path. Zenity observed substantial restrictions to the role on September 29, but did not confirm when those changes rolled out. The findings make narrowly scoped custom roles important because blocking one credential path does not fix excessive permissions.
01
A prompt could direct an agent to reach AWS’s Instance Metadata Service and retrieve its temporary credentials.
02
The default role could discover agent identifiers, invoke agents, and pull their container images across the region.
03
Zenity found the role also allowed API-key retrieval and access to AWS Secrets Manager, weakening AgentCore Gateway’s credential separation.
A public-facing AI chat could become an entry point to private agents elsewhere in the same AWS account and region. In research published October 8, Zenity Labs said one prompt could extract an Amazon Bedrock AgentCore agent’s temporary credentials, then use its broad default permissions to reach other agents. AWS has since tightened those permissions, the researchers said.
Researchers Tamir Ishay Sharbat and Lana Salameh called the vulnerability chain AgentCorruption. Their findings concern AgentCore, AWS’s managed platform for deploying and operating AI agents with tools and memory. The chain combined access to internal credentials with permissions that extended well beyond the agent receiving the prompt.
The chat window hid a much larger permission boundary
The first step exploited a tool capable of making web requests. Zenity found that such tools could reach the Instance Metadata Service, an internal AWS service that supplies temporary credentials to workloads. A malicious prompt directed the agent to request those credentials from inside its own computing environment.
The second step was not another conversation with the model. The credentials carried the authority of AgentCore’s default execution role—the rules governing what the agent could access. That role was not limited to one agent. Zenity found permissions to discover agent identifiers, invoke other agents and pull their container images across the region.
The consequences went beyond running another agent. The researchers could read private conversations across agents, users and sessions. For agents with long-term memory enabled, they could also create memories that changed future behavior. That made the manipulation persistent: a later conversation could be influenced by instructions planted through a direct cloud request.
Separate credential storage did not prevent another route to exposure. AgentCore Gateway handles authentication when agents call connected tools, keeping those tools’ credentials away from the agent itself. But the default role also allowed API-key retrieval and access to AWS Secrets Manager, undermining that separation, Zenity found.
Two fixes addressed different links in the chain
Zenity disclosed the metadata-access issue to AWS on December 25, 2025. According to its disclosure timeline, AWS later said newly deployed agents had used only IMDSv2, the second version of the metadata service, since February 14, 2026. That change addressed the credential-access step rather than the breadth of the role’s permissions.
The researchers separately reported the overprivileged role on January 12. Their June 22 review found it unchanged. On September 29, during a final review before publication, they observed substantial restrictions. That is an observation date, not a confirmed rollout date for the permission changes.
Zenity still recommends assigning agents custom roles with narrower access rights, according to The Decoder. The recommendation focuses on limiting what compromised credentials can authorize, rather than relying solely on an agent to reject a malicious instruction.
Sources
labs.zenity.ioSecurity Research | AgentCorruption: How A Single Prompt Collapsed The Entire Cloud Security Model | Zenity Labs
the-decoder.comA single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found
Reader comments
Newest comments first. Replies stay oldest first.