Researchers poked holes in sandboxed Bedrock AgentCore code interpreters—and found a way to leak execution role credentials through the MicroVM Metadata Service (MMDS). No outside network? Doesn’t matter. The exploit dodges basic string filters in requests and lets non-agentic code swipe AWS creds to hit control plane APIs from the outside.