Why AI agents are a risk
An AI agent decides what to do based on the content it reads, and an attacker can write some of that content. The agent then acts with the IAM role and the tools you gave it. For example, an AI agent for customer support answers messages and can look up orders. An attacker sends a message that tells the agent to paste another customer’s orders into the reply. The agent treats the message as an instruction and follows it. Its IAM role and tools allow the lookup, so the attacker gets the orders. To limit the damage, you need to know which agents you have and which roles and tools they use.How it works
Plerion reads your agents’ configuration through the AWS integration you already have. You do not install anything or add code to your agents. For now, Agent security works with AWS only, and only with agents on Amazon Bedrock. Agents you host yourself, outside Amazon Bedrock, are not covered. Amazon Bedrock AgentCore is an AWS service for building and running AI agents. Agent security covers three kinds of agent:- AgentCore runtimes: you supply the agent code or a container image.
- AgentCore harnesses: you define a model, tools, and instructions.
- Amazon Bedrock Agents Classic agents: built with the earlier Amazon Bedrock Agents service.
What Plerion shows about your agents
OpenAgent security in the left navigation to see your agents in every account and region. For these agents, Plerion shows:
- For all agents, the IAM role they run as and their risk score
- For AgentCore runtimes and harnesses, whether they run in a VPC and how their callers are authorized
- For AgentCore harnesses, the gateways they call tools through, their AgentCore memory, and the credential providers they use to sign in to other services
- A gateway anyone can call
- A gateway with no policy engine
- A policy engine that logs decisions without enforcing them
- A Cedar policy that allows any caller
- A runtime, gateway, or memory that an account outside your AWS organization can access
- Secrets left in an agent’s environment variables or configuration
- A runtime or harness that runs outside a VPC
- A harness that calls a remote tool server over plain HTTP
- Vulnerabilities and secrets in a runtime’s container image
- An Amazon Bedrock Agents Classic agent with no guardrail
- A region with model invocation logging turned off