Executive brief
Amazon Strands Agents Tools is a library providing pre-built tools for building AI agents that can execute system commands on a host machine. A prompt injection vulnerability in the shell tool allows attackers to bypass the human approval gate and execute arbitrary operating system commands with the privileges of the agent process by injecting crafted text into content the agent reads, such as web pages or messages.
Technical details
This is a prompt injection vulnerability (CWE-1427) in the shell tool component of Strands Agents Tools. The shell tool exposes a non_interactive parameter in its LLM-controllable input schema; when set to true, this parameter bypasses the human consent gate that normally requires operator approval before executing commands. An attacker can indirectly inject a crafted prompt into untrusted content (web pages, Slack messages, files) that the agent reads, causing the LLM to set non_interactive=true in the same tool call, thereby skipping the approval gate. The attacker can then execute arbitrary OS commands with the privileges of the agent process. The vulnerability affects versions before 0.8.0 and requires user interaction (the agent must process untrusted content) but no authentication. The issue is patched in version 0.8.0, where the non_interactive parameter can no longer bypass the consent gate.
Affected products
- Amazon Strands Agents Tools before 0.8.0
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Version 0.8.0 released with fix