Zenity says one prompt exposed every AgentCore agent in an AWS account and region. The researchers used a public agent to obtain temporary AWS credentials, then exploited default permissions that reached other agents’ code, conversations and stored secrets. AWS changed the platform’s defaults after Zenity reported the flaws, but the episode raises a harder question than whether one access path was closed: how much isolation can a cloud agent platform provide when agents are built to use tools and shared resources?