A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Palo Alto Networks, Friday, September 18th, 2026
Unit 42 research on credential exposure risks in AWS AgentCore's harness and identity boundary.
Unit 42 examines the security boundary between the AWS AgentCore harness and the identity layer that supplies credentials to agents.
The research shows how the memory and process space in which an agent harness runs can expose secrets that were intended to stay scoped to a narrow operation.
It details the conditions under which credentials become recoverable and what that means for blast radius when an agent is compromised. Unit 42 offers configuration and architectural guidance for teams deploying agentic workloads on AWS.