Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: strands-agents/shell

SECURITY.md

Security Policy

Supported Versions

Strands Shell is pre-1.0 and under active development. Security fixes are applied to the latest released version.

What Is a Security Issue

Strands Shell is an in-process mediation layer for AI agents, not a hardened sandbox. A bypass of any control that the Kernel boundary is meant to enforce is treated as a security issue, including:

  • Reading or writing files beyond explicitly bound paths (filesystem mediation bypass)
  • Defeating SSRF and metadata-service protections (e.g. reaching RFC1918, link-local, loopback, or IMDS/ECS-task-role addresses through curl or http_request)
  • Exfiltrating or misrouting injected HTTP credentials (credential injection bypass)
  • Escaping Kernel mediation to make direct syscalls, fork/exec, or otherwise reach the host environment
  • Crafted input that causes the shell engine to panic, consume unbounded memory, or hang indefinitely (e.g. unbounded recursion in the parser, Lua memory exhaustion without limits)
  • Injected credentials appearing in command output, error messages, environment variable dumps, or the Lua scripting context accessible to the agent
  • Using symlinks, .. components, or race conditions in bind mounts to escape the declared filesystem boundary
  • Discrepancies between how the SSRF guard parses a URL and how the HTTP client interprets it (e.g. userinfo injection, encoding tricks, scheme confusion)
  • Any mechanism that causes credentials to be sent to a destination other than the originally-matched URL prefix, including via redirects
  • One MCP client session accessing state (VFS, environment, credentials) belonging to another session on the same server process

Security Architecture

The security boundary is the Kernel trait (src/os.rs). All filesystem, network, and credential operations flow through this interface. The default VfsKernel implementation enforces:

  1. Filesystem isolation — in-memory VFS with explicit bind mounts; no path can escape declared mounts
  2. Network SSRF guard — two-layer check: URL-level parse + DNS-resolution-time IP filtering via SafeResolver. Blocks RFC1918, link-local, loopback, IMDS, IPv4-mapped-IPv6, 6to4, Teredo
  3. Credential injection — per-URL prefix matching with path-boundary checks; credentials injected only on original request, stripped on redirects
  4. No syscalls — pure userspace shell; no fork, exec, or raw syscall paths

Custom Kernel implementations (for embedding in other runtimes) carry their own security properties. Reports about the VfsKernel implementation are in scope; reports about third-party Kernel implementations should go to those maintainers.

Out of Scope

The following are explicitly not part of the security boundary and will not be treated as security issues:

  • Resource exhaustion via CPU/memory within configured limits (limits are best-effort, use OS-level cgroups for hard guarantees)
  • Speculative execution and side-channel attacks (same-process architecture, use VM isolation for this threat model)
  • Multi-tenancy within a single OS process (documented non-goal, one Shell instance per session is the contract)
  • Agent reading files it was explicitly granted access to via binds (working as designed, the bind is the grant)
  • Lua scripts consuming memory up to configured limits (limits are advisory, Lua sandbox is not a security boundary)

See the Security Model in the README for the full threat model and guidance on running Strands Shell inside VM- or container-level isolation when stronger guarantees are required.

Reporting Security Issues

Amazon Web Services (AWS) is dedicated to the responsible disclosure of security vulnerabilities.

We kindly ask that you do not open a public GitHub issue to report security concerns.

Instead, please submit the issue to the AWS Vulnerability Disclosure Program via HackerOne or send your report via email.

For more details, visit the AWS Vulnerability Reporting Page.

Thank you in advance for collaborating with us to help protect our customers.

There aren't any published security advisories