Amazon Bedrock agents with no guardrail associated
What does ZopNight detect here?
ZopNight flags Amazon Bedrock agents that have no guardrail attached through their `guardrailConfiguration`. Without a guardrail, prompts and responses pass through no content filters, denied topics or PII redaction. This is a high-severity security finding with no dollar saving, and ZopNight stays silent when it cannot confirm the agent's guardrail status.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1630 |
| Category | security |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | no guardrail associated with the agent |
| Source | ZopNight |
| Permissions used | bedrock:ListAgents · bedrock:GetAgent |
Where it applies
Agents act on user input, so unfiltered input is a risk
A Bedrock agent takes a user’s message, reasons over it with a foundation model and can call action
groups or knowledge bases. AWS’s
agent guardrail page
recommends associating a guardrail to prevent unwanted behaviour from model responses or user
messages, and says you do it by specifying a GuardrailConfiguration in a CreateAgent or
UpdateAgent request. An agent without one relies entirely on the model’s own behaviour: no denied
topics, no content filters and no masking of personal data.
Checking agents for a guardrail
aws bedrock-agent list-agents --query 'agentSummaries[].[agentId,agentName,agentStatus]' --output table
aws bedrock-agent get-agent --agent-id AGENT12345 \ --query 'agent.[agentName,guardrailConfiguration]'An empty guardrailConfiguration means no guardrail is associated. The
GuardrailConfiguration reference
shows it holds a guardrail identifier and a version, either a number or DRAFT.
When ZopNight raises it
ZopNight records, for every agent, whether a guardrail is attached. The finding appears only when that record says no guardrail. There is no metric, threshold or lookback: it is a configuration check, repeated each evaluation.
When it holds back
If ZopNight could not determine the agent’s guardrail status, for example because the lookup failed, it raises nothing rather than report a gap it has not confirmed. Agents with any guardrail attached are clear, whatever that guardrail contains; checking the guardrail’s own policies is the job of Bedrock Guardrail Missing PII / Sensitive-Information Protection.
A safety gap, not a cost
This finding carries no savings figure. The exposure is an agent that can be steered into harmful or off-policy answers, or that repeats personal data such as names and email addresses back to users or into downstream tools.
Attaching a guardrail
- Create a guardrail, or choose an existing one, with the content filters, denied topics and sensitive information filters the workload needs, then publish a version.
- Associate it with the agent.
update-agentalso requires the agent’s name, foundation model and service role, so pass the current values:
aws bedrock-agent update-agent --agent-id AGENT12345 --agent-name support-agent \ --foundation-model your-model-id \ --agent-resource-role-arn arn:aws:iam::123456789012:role/BedrockAgentRole \ --guardrail-configuration guardrailIdentifier=gr-abc123,guardrailVersion=1- Prepare the agent so the change takes effect:
aws bedrock-agent prepare-agent --agent-id AGENT12345 - Send a test prompt that should be blocked and confirm the guardrail message comes back.