get_agent_blast
What can a hijacked AI agent reach in this AWS account?
Instructions
What can a hijacked AI agent reach in this AWS account?
For every Bedrock Agent, AgentCore runtime, gateway or sandbox found by the
last scan (or the one matching agent by name, id or ARN substring),
returns a Markdown report under two threat models: identity takeover (the
attacker holds the agent role's credentials) and behaviour takeover (prompt
injection steering the agent's tools, bounded by the tools' execution
roles), with data, secret, lateral and code-execution reach and OWASP
Agentic / MITRE ATLAS tags. Computed from the saved scan, no AWS calls.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |