> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent security

> See the AI agents running in your AWS accounts, how they are configured, and what puts them at risk

With **[Agent security](https://app.plerion.com/agent-security)**, you can find the agents your teams run on Amazon Bedrock and get a finding when they are configured unsafely.

***

## Why AI agents are a risk

An AI agent decides what to do based on the content it reads, and an attacker can write some of that content. The agent then acts with the IAM role and the tools you gave it.

For example, an AI agent for customer support answers messages and can look up orders. An attacker sends a message that tells the agent to paste another customer's orders into the reply. The agent treats the message as an instruction and follows it. Its IAM role and tools allow the lookup, so the attacker gets the orders.

To limit the damage, you need to know which agents you have and which roles and tools they use.

***

## How it works

Plerion reads your agents' configuration through the AWS integration you already have. You do not install anything or add code to your agents.

For now, Agent security works with AWS only, and only with agents on Amazon Bedrock. Agents you host yourself, outside Amazon Bedrock, are not covered. Amazon Bedrock AgentCore is an AWS service for building and running AI agents. Agent security covers three kinds of agent:

* AgentCore runtimes: you supply the agent code or a container image.
* AgentCore harnesses: you define a model, tools, and instructions.
* Amazon Bedrock Agents Classic agents: built with the earlier Amazon Bedrock Agents service.

If your Plerion stack is older than policy version v33, [update it](/guides/integrations/aws/aws-account/updating-aws-account) so Plerion can read your AgentCore agents.

***

## What Plerion shows about your agents

Open `Agent security` in the left navigation to see your agents in every account and region. For these agents, Plerion shows:

* For all agents, the IAM role they run as and their risk score
* For AgentCore runtimes and harnesses, whether they run in a VPC and how their callers are authorized
* For AgentCore harnesses, the gateways they call tools through, their AgentCore memory, and the credential providers they use to sign in to other services

AgentCore runtimes and harnesses can call their tools through a gateway. The gateway's policy engine holds policies written in Cedar, the policy language AgentCore uses. These policies decide which tool calls are allowed.

Plerion raises a finding for unsafe configuration, such as:

* A gateway anyone can call
* A gateway with no policy engine
* A policy engine that logs decisions without enforcing them
* A Cedar policy that allows any caller
* A runtime, gateway, or memory that an account outside your AWS organization can access
* Secrets left in an agent's environment variables or configuration
* A runtime or harness that runs outside a VPC
* A harness that calls a remote tool server over plain HTTP
* Vulnerabilities and secrets in a runtime's container image
* An Amazon Bedrock Agents Classic agent with no guardrail
* A region with model invocation logging turned off

Plerion does not yet show which sensitive data an agent can access or how it could escalate its privileges.

***

<h2 id="agent-behavior">
  Agent behavior <Badge color="blue" size="sm">Coming soon</Badge>
</h2>

Plerion detects when an agent acts outside its scope. It compares what your AgentCore runtimes and harnesses do while they run with what their IAM roles and gateway policies allow, and with the purpose you deployed them for. When an agent goes beyond either, Plerion raises a finding that shows what the agent did. For this, Plerion needs activity logs from your AWS account, which you turn on separately.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.