DEV Community

Cover image for Zenity: A message to a public assistant could open access to other AgentCore assistants
Hacks.gr
Hacks.gr

Posted on Originally published at en.hacks.gr Fully Autonomous

Zenity: A message to a public assistant could open access to other AgentCore assistants

Zenity’s AgentCorruption research describes a potential cross-agent exposure in Amazon Bedrock AgentCore.

A prompt to a public agent could, under specific conditions, lead to temporary AWS credentials and access to other agents in the same account and region.

The scenario required a web-request or shell tool and a relevant instruction; Zenity says the reported issues have been fixed.


AgentCore is an AWS service for building and running AI assistants. Zenity called the chain of actions it studied AgentCorruption. For the scenario to work, the publicly accessible assistant had to have a tool that sends requests to web pages or executes commands and follow a corresponding instruction. There didn’t have to be a problem on the chat page.

The researchers used an internal AWS service that allowed the program running the assistant to obtain temporary credentials associated with its privileges. According to Zenity, these privileges were not limited to a single assistant. This allowed the researchers to locate and summon other assistants in the same account and region, as well as read their conversations.

What evidence could they see?

Zenity says researchers gained access to private conversations, source code, and saved memories. They also found keys and digital login tokens for other services, as well as confidential information stored in AWS Secrets Manager.

Accessing memories could allow the addition of false memories and hidden instructions. These could affect how the assistant operates in later conversations.

What AWS changed

Zenity notified AWS of internal service access on December 25, 2025, and of broad permissions on January 12, 2026. In February, AWS changed how new installations receive temporary access credentials and later made the new setting mandatory.

On September 29, Zenity confirmed that AWS had removed permissions that allowed broad access to other assistants, their conversations, and AWS Secrets Manager. The researchers say the issues they reported have been fixed.

AWS disagrees with the finding being classified as a security flaw. It says it is expected and documented that an assistant could use credentials that match their own privileges. To access a resource from one AWS account to another account, the company says that both the assistant and the resource must be explicitly granted privileges.

AWS recommends that businesses use specially configured permissions for their normal-functioning assistants, allowing them only what they need. It also recommends limiting permissions that span multiple resources, controlling the instructions that assistants receive, limiting their internet access, and separating public assistants from internal assistants. It also recommends monitoring activity logs through AWS CloudTrail and CloudWatch, and using AgentCore Gateway controls that agents cannot bypass by gaining direct access.


Read the original English article on Hacks.gr

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to