A default-enabled shell in AgentCore Harness can be exploited through prompt injection, allowing attackers to execute commands and extract plaintext credentials from the harness process memory, putting sensitive data at risk. This simple yet consequential chain highlights a critical vulnerability in credential security.
Survey Before Sale