Research investigation R1009 / claim audit
AgentCore’s MMDSv2 Requirement Leaves Existing Sessions Unaffected
The sampled records distinguish invocation-time metadata enforcement from generated IAM policy changes. They establish configuration requirements and narrower toolkit templates, but not automatic migration of previously created customer roles.
The evidence_matrix supports a deployment-cohort checklist, not a vulnerability prevalence estimate. New-deployment metadata behavior is established only as an AWS statement reproduced by Zenity. Existing runtime invocation requirements and the existing-session exception are documented by AWS. Toolkit policy changes are identifiable in source, while migration of previously created roles remains unresolved in this sample. AWS’s explicit no-automatic-migration statement for agents created before October 13, 2025 concerns workload identity only and must remain separate from the metadata and execution-role remediation audit.
The evidence_matrix supports a deployment-cohort checklist, not a vulnerability prevalence estimate. New-deployment metadata behavior is established only as an AWS statement reproduced by Zenity. Existing runtime invocation requirements and the existing-session exception are documented by AWS. Toolkit policy changes are identifiable in source, while migration of previously created roles remains unresolved in this sample. AWS’s explicit no-automatic-migration statement for agents created before October 13, 2025 concerns workload identity only and must remain separate from the metadata and execution-role remediation audit.
- Dataset ID
- spd:agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d
- Stable URL
- /research/agentcore-s-security-changes-which-protections-reach-existing-deployments-23b8092d
- Version
- Live
- Coverage
- Live collection
- Records
- 0
- Fields
- 7
- Updated
| Entity | Metric | Value | Unit | Observed | Source | Transform |
|---|
Measurement technique
How to read this report
- 01Synthesize the saved evidence without new collection or execution, preserving the original cutoff of October 9, 2026, 02:31 UTC and collection-context timestamp 2026-10-09T02:31:40.230Z.
- 02Use the bounded sample of Zenity’s disclosure, AWS metadata, permissions and identity documentation, toolkit pull request 554, and the v0.3.10 and v0.3.14 execution-role templates.
- 03Build an evidence_matrix separating new deployments, existing runtime invocations, existing sessions, newly generated toolkit policies and previously created customer roles. Record source, creation path, applicability, documented customer action and unresolved coverage for each row.
- 04Classify documentary applicability as established, customer-action-dependent or unresolved. An established requirement is not proof that a customer deployment complies with it.
- 05Compare conditional template branches rather than infer deployed account policies: runtime/* becomes runtime/agent_name-*, memory/* becomes memory/agent_name_mem-*, and the newer template omits the older conditional CreateMemory grant.
- 06Keep chronology and creation paths separate: Zenity attributes February 14 metadata changes to AWS correspondence; toolkit hardening merged July 27; Zenity observed role restrictions September 29. Do not assume these describe the same rollout.
Sources
Evidence
4 publishers supporting 0 records. Expand a publisher to inspect its cited pages.