What the checker looks for
Each check comes from AWS's own security guidance for AgentCore. Where AWS Security Hub has a control for the same setting, the finding names it: that control fails the resource once it is deployed.
| Resource | Checked | Security Hub |
|---|---|---|
| Runtime | PUBLIC network mode; JWT authorizer without audiences or clients; AWS keys and secrets in environment variables; MMDSv2 | BedrockAgentCore.1 (High) |
| Gateway | NONE or AUTHENTICATE_ONLY inbound auth without a policy engine in ENFORCE mode or an interceptor; JWT restrictions; policy engine in LOG_ONLY; ExceptionLevel: DEBUG; no customer managed key | BedrockAgentCore.2 (High), .4 (Medium) |
| Code Interpreter | PUBLIC or SANDBOX network mode | BedrockAgentCore.7 (High) |
| Browser | PUBLIC network mode; session recording off | BedrockAgentCore.5 (High), .6 (Medium) |
| Memory | No customer managed key | BedrockAgentCore.3 (Medium) |
| API key and OAuth2 credential providers | The API key or client secret written in the template, or kept in Terraform state | - |
| Resource policy | Principal: "*" without a condition | - |
| IAM roles AgentCore can assume | Trust policy without aws:SourceAccount or aws:SourceArn; AdministratorAccess or "Action": "*" | - |
A gateway with AuthorizerType: NONE is the one to fix first: anyone who finds its URL can list and call its tools. AWS allows it only for gateways meant to be public, with your own throttling, and with authorization moved to a policy engine, an interceptor Lambda function or the targets. AUTHENTICATE_ONLY checks the SigV4 signature but not the caller's permissions, so any IAM principal gets through. The AgentCore Token Flow Planner shows how to set up the JWT authorizer instead.
Environment variables are no place for API keys: GetAgentRuntime returns them in plain text to anyone allowed to read the runtime. An AgentCore Identity API key credential provider or a Secrets Manager secret read at startup keeps them out of the configuration. In Terraform, a secret from a variable still ends up in the state file, unless it goes through the write-only api_key_wo or client_secret_wo (Terraform 1.11+) or an external Secrets Manager secret.
What a template cannot show
- MMDSv2. Since June 30, 2026 AgentCore Runtime rejects invocations of a runtime whose
metadataConfiguration.requireMMDSV2is nottrue. Neither CloudFormation'sAWS::BedrockAgentCore::Runtimenor Terraform'saws_bedrockagentcore_agent_runtimedocuments the setting yet, so check the deployed runtime:aws bedrock-agentcore-control get-agent-runtime --agent-runtime-id RUNTIME_ID --query metadataConfiguration, and set it withUpdateAgentRuntimeif it isnull. - Policies attached elsewhere. The checker reads a role's inline policies, its managed policy ARNs and, in Terraform, the
aws_iam_role_policyandaws_iam_role_policy_attachmentresources that reference it - not separate CloudFormationAWS::IAM::Policyresources or modules. - Session-to-user mapping. AgentCore does not tie a session ID to a user; your backend must.
- Input validation. AWS warns that a non-string
prompt- a list of content blocks withtoolUse- can make an agent framework call a tool without the model. Validate the payload in your entrypoint.
Why IaC scanners miss AgentCore
On September 30, 2026 none of the open-source IaC scanners had AgentCore rules: Checkov's only Bedrock checks are for classic Bedrock Agents (a customer managed key) and Guardrails, and Trivy, KICS and AWS's CloudFormation Guard rules registry have none. AWS Security Hub has seven AgentCore controls, but they evaluate resources after they are deployed, through AWS Config rules that react to configuration changes. This checker runs on the template, before the deploy.
Frequently asked questions
Is my template sent anywhere?
No. It is read in your browser: nothing you paste is uploaded, processed on a server or stored. The page only counts that the checker was used, with which format and which first finding, never the template.
Does it work with CDK?
Yes, through what CDK deploys: run cdk synth and paste the template it prints, or the JSON template from cdk.out. The same goes for SAM templates, which are CloudFormation.
Is PUBLIC network mode wrong?
Not necessarily - it is what most examples use. In PUBLIC mode the agent reaches the internet directly, and your security groups, network ACLs and VPC flow logs do not apply to its traffic. Security Hub fails it (High); VPC mode needs private subnets with a NAT gateway for internet access, and VPC endpoints for ECR, S3 and CloudWatch Logs.
Why does a code interpreter in SANDBOX mode get a note?
Sandbox mode already limits the code to Amazon S3, and AWS offers it for exactly that case. Security Hub's control BedrockAgentCore.7 still fails anything but VPC mode, so the note tells you what the control will say.
Why does the trust policy need aws:SourceAccount?
Without a condition, any AgentCore resource that is given the role's ARN can have AgentCore assume it - the confused deputy problem. aws:SourceAccount limits it to your account, aws:SourceArn to your AgentCore resources.
References
Security best practices for AgentCore Runtime
Security Hub CSPM controls for Amazon Bedrock AgentCore
Set up inbound authorization for your gateway
Configure inbound JWT authorizer
Turn on debugging messages
Bedrock AgentCore resource type reference (CloudFormation)