FREE TOOL

AgentCore IaC Security Checker

Paste a CloudFormation template or Terraform and check its Amazon Bedrock AgentCore resources before you deploy: gateways without authorization, secrets in the template, PUBLIC network modes, JWT authorizers and execution roles.

  • Your data never leaves your browser: everything is calculated by JavaScript on this page, not on a server.
  • Nothing you enter is uploaded, processed on a server or stored. Check it in your browser's developer tools (Network tab).
  • Once the page has loaded, the tool works without an internet connection.

Template

A CloudFormation template in YAML or JSON (SAM and cdk synth output too) or Terraform with the aws provider - the whole file or just the AgentCore resources. It is read here and never leaves your browser.

Read as CloudFormation

Or try an example

See the check ↓
Least-privilege roles, confused deputies, secrets management and KMS keys are AWS Security Specialty topicsTry free SCS-C02 practice questions with answers and explanations.SCS-C02 questions →

What the checker looks for

Each check comes from AWS's own security guidance for AgentCore. Where AWS Security Hub has a control for the same setting, the finding names it: that control fails the resource once it is deployed.

ResourceCheckedSecurity Hub
RuntimePUBLIC network mode; JWT authorizer without audiences or clients; AWS keys and secrets in environment variables; MMDSv2BedrockAgentCore.1 (High)
GatewayNONE or AUTHENTICATE_ONLY inbound auth without a policy engine in ENFORCE mode or an interceptor; JWT restrictions; policy engine in LOG_ONLY; ExceptionLevel: DEBUG; no customer managed keyBedrockAgentCore.2 (High), .4 (Medium)
Code InterpreterPUBLIC or SANDBOX network modeBedrockAgentCore.7 (High)
BrowserPUBLIC network mode; session recording offBedrockAgentCore.5 (High), .6 (Medium)
MemoryNo customer managed keyBedrockAgentCore.3 (Medium)
API key and OAuth2 credential providersThe API key or client secret written in the template, or kept in Terraform state-
Resource policyPrincipal: "*" without a condition-
IAM roles AgentCore can assumeTrust policy without aws:SourceAccount or aws:SourceArn; AdministratorAccess or "Action": "*"-

A gateway with AuthorizerType: NONE is the one to fix first: anyone who finds its URL can list and call its tools. AWS allows it only for gateways meant to be public, with your own throttling, and with authorization moved to a policy engine, an interceptor Lambda function or the targets. AUTHENTICATE_ONLY checks the SigV4 signature but not the caller's permissions, so any IAM principal gets through. The AgentCore Token Flow Planner shows how to set up the JWT authorizer instead.

Environment variables are no place for API keys: GetAgentRuntime returns them in plain text to anyone allowed to read the runtime. An AgentCore Identity API key credential provider or a Secrets Manager secret read at startup keeps them out of the configuration. In Terraform, a secret from a variable still ends up in the state file, unless it goes through the write-only api_key_wo or client_secret_wo (Terraform 1.11+) or an external Secrets Manager secret.

What a template cannot show

  • MMDSv2. Since June 30, 2026 AgentCore Runtime rejects invocations of a runtime whose metadataConfiguration.requireMMDSV2 is not true. Neither CloudFormation's AWS::BedrockAgentCore::Runtime nor Terraform's aws_bedrockagentcore_agent_runtime documents the setting yet, so check the deployed runtime: aws bedrock-agentcore-control get-agent-runtime --agent-runtime-id RUNTIME_ID --query metadataConfiguration, and set it with UpdateAgentRuntime if it is null.
  • Policies attached elsewhere. The checker reads a role's inline policies, its managed policy ARNs and, in Terraform, the aws_iam_role_policy and aws_iam_role_policy_attachment resources that reference it - not separate CloudFormation AWS::IAM::Policy resources or modules.
  • Session-to-user mapping. AgentCore does not tie a session ID to a user; your backend must.
  • Input validation. AWS warns that a non-string prompt - a list of content blocks with toolUse - can make an agent framework call a tool without the model. Validate the payload in your entrypoint.

Why IaC scanners miss AgentCore

On September 30, 2026 none of the open-source IaC scanners had AgentCore rules: Checkov's only Bedrock checks are for classic Bedrock Agents (a customer managed key) and Guardrails, and Trivy, KICS and AWS's CloudFormation Guard rules registry have none. AWS Security Hub has seven AgentCore controls, but they evaluate resources after they are deployed, through AWS Config rules that react to configuration changes. This checker runs on the template, before the deploy.

Frequently asked questions

Is my template sent anywhere?

No. It is read in your browser: nothing you paste is uploaded, processed on a server or stored. The page only counts that the checker was used, with which format and which first finding, never the template.

Does it work with CDK?

Yes, through what CDK deploys: run cdk synth and paste the template it prints, or the JSON template from cdk.out. The same goes for SAM templates, which are CloudFormation.

Is PUBLIC network mode wrong?

Not necessarily - it is what most examples use. In PUBLIC mode the agent reaches the internet directly, and your security groups, network ACLs and VPC flow logs do not apply to its traffic. Security Hub fails it (High); VPC mode needs private subnets with a NAT gateway for internet access, and VPC endpoints for ECR, S3 and CloudWatch Logs.

Why does a code interpreter in SANDBOX mode get a note?

Sandbox mode already limits the code to Amazon S3, and AWS offers it for exactly that case. Security Hub's control BedrockAgentCore.7 still fails anything but VPC mode, so the note tells you what the control will say.

Why does the trust policy need aws:SourceAccount?

Without a condition, any AgentCore resource that is given the role's ARN can have AgentCore assume it - the confused deputy problem. aws:SourceAccount limits it to your account, aws:SourceArn to your AgentCore resources.

References

Security best practices for AgentCore Runtime
Security Hub CSPM controls for Amazon Bedrock AgentCore
Set up inbound authorization for your gateway
Configure inbound JWT authorizer
Turn on debugging messages
Bedrock AgentCore resource type reference (CloudFormation)