← Back to news
The Register - Security9 Oct 2026 · 2 min read

Prompt-based credential requests highlight risks for AWS AgentCore deployments

A reported security issue involving AWS AgentCore has drawn attention to the risks of allowing AI agents to process untrusted instructions while they have access to cloud credentials or sensitive inte...

A reported security issue involving AWS AgentCore has drawn attention to the risks of allowing AI agents to process untrusted instructions while they have access to cloud credentials or sensitive internal tools.

The concern centers on prompt injection, a class of attack in which malicious content is embedded in material an AI system is asked to read or act on. If an agent treats that content as an authorized instruction, it could be persuaded to request, disclose, or misuse credentials depending on the permissions and integrations available to it.

Why agent permissions matter

AI agents can be configured to retrieve data, call APIs, use development tools, and interact with cloud services. Those capabilities can improve automation, but they also create a security boundary that must be managed independently of the model's ability to follow natural-language directions.

A prompt that asks an agent for credentials should not, by itself, be able to override identity controls. However, organizations may face exposure if agents can access secrets through broad roles, return sensitive tool output to users, or follow instructions contained in webpages, tickets, documents, or other external sources.

  • Apply least-privilege IAM roles and limit each agent to the APIs and resources required for its task.
  • Keep secrets in dedicated secret-management services rather than in prompts, files, or agent-readable configuration where possible.
  • Require explicit authorization and validation before agents perform sensitive actions or reveal tool results.
  • Separate trusted operator instructions from untrusted retrieved content, including data collected from external websites.
  • Log agent activity, tool calls, and permission changes to support detection and incident response.
  • Test agent workflows for prompt-injection scenarios before production deployment.

The incident illustrates that safeguards for AI agents cannot rely solely on system prompts or behavioral rules. Effective protection requires conventional cloud security measures, constrained tool access, careful handling of external content, and monitoring for attempts to influence automated workflows.

Share this article:TwitterLinkedIn