Your AI agent can read its own vault secret
AWS AgentCore Harness copies vault secrets into its own memory as plaintext, where its default shell tool can read them. In a lab with a permissive model, Unit 42 stole a token through a support ticket and used it from a laptop. AWS closed the report as informative, pointing to customer-side controls.