security: fail closed on ambient AWS credential fallback
Maintainers usually reply within 1 day
@scottschreckengaust is already working on this.
Since Sep 15, 2026.
Assessment
This issue has not been assessed yet.
Description
Problem
agent/src/bedrock_creds_helper.py returns ambient compute-role credentials when the attribution file is missing, malformed, or STS credential issuance fails.
Repository-controlled code can invoke the helper with a nonexistent attribution file, parse the credentials written to stdout, and use the compute role outside the intended task boundary. The role currently has permissions that may expose cross-workspace provider secrets and shared task resources.
Required behavior
Credential issuance must fail closed whenever task attribution is absent, malformed, forged, or cannot be validated.
Ambient compute credentials must never be returned to repository-controlled processes.
Scope
- Remove ambient credential fallbacks from
agent/src/bedrock_creds_helper.py. - Ensure task identity comes from trusted, immutable state.
- Reduce compute-role permissions to bootstrap-only access where possible.
- Remove direct repository access to wildcard provider-secret and shared-state permissions.
Acceptance criteria
- Missing attribution files return an error and no credential JSON.
- Malformed and forged attribution files return an error and no credentials.
- STS failures do not fall back to ambient credentials.
- Tests verify repository UID execution cannot obtain ambient credentials.
- IAM tests verify compute roles cannot read wildcard workspace secrets or modify shared concurrency state.
- Bedrock calls continue to work through validated task identity.
- Dominant language
- TypeScript
- Stars
- 154
- Forks
- 48
- Avg merge
- 3d 23h
- Merged PRs (30d)
- 21
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws-samples/sample-autonomous-cloud-coding-agents
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
aws-samples/sample-autonomous-cloud-coding-agents#908 ·
Maintainers usually reply within 1 day
-
bug v1
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
aws-samples/sample-autonomous-cloud-coding-agents#886 ·
Maintainers usually reply within 1 day
-
bug v1
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
aws-samples/sample-autonomous-cloud-coding-agents#861 ·
Maintainers usually reply within 1 day
-
documentation P2 security
Difficulty 2/5 1-2 days Newbie friendliness 74/100
aws-samples/sample-autonomous-cloud-coding-agents#793 ·
Maintainers usually reply within 1 day
-
Docs: How to clear previously set attributes for a blueprintMay be free again @rkumarus-aws claimed this 39 days ago, and no pull request is open. Opendocumentation
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
aws-samples/sample-autonomous-cloud-coding-agents#767 · 2 comments ·
Maintainers usually reply within 1 day
All issues in aws-samples/sample-autonomous-cloud-coding-agents
Similar issues
-
[Bug] The clients language filter cannot select the rows the page labels as unknownPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
apache/rocketmq-dashboard#6103 ·
Maintainers usually reply within 4 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
cockpit-project/cockpit-machines#2835 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
cloudflare/kumo#866 ·
Maintainers usually reply within 1 day
-
area:connector bug
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
autoInject recall silently drops memory injection on long / non-Latin prompts (HTTP 400 Query too long)Possibly taken @Epsilon006 claimed this today. Openintegration:coding-agents
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
vectorize-io/hindsight#5476 · 1 comment ·
Maintainers usually reply within 1 day