aws-bedrock-agent-instruction-prompt

Agent instructions and prompt overrides are persisted customer text and can expose sensitive operational data.

awscritical service: aws:bedrock emits ContainsCredential

Where it sits

locationbedrock-agent:GetAgent.agent.instruction / promptOverrideConfiguration
location kindtemplate_document
data kindscredential password api_key customer_data pii source_code_secret
emits edgeContainsCredential
serviceBedrock (aws:bedrock)

Collection recipe

access moderead_api
operationGetAgent
response pathagent.{instruction,promptOverrideConfiguration}
encodingjson
params{"agentId": "\u003cagent-id\u003e"}

Required permissions

bedrock:GetAgent

References

move · open · esc close