The scenario
A startup shipped a Bedrock-backed customer-support assistant fast. It calls
Amazon Nova Lite (amazon.nova-lite-v1:0) with a system prompt that includes
some "internal notes" — never meant for customers — and simply tells the model
not to repeat them. That's it. No independent control backs up that instruction.
Your job: prove the leak, then close it.
What you'll do
First you'll break it — prompt-inject the assistant into leaking its restricted notes (this proves the vulnerability; it isn't graded). Then you'll close three real gaps:
- No Guardrail — attach one with a denied topic that blocks the leak
- An over-broad invoke role — scope
bedrock:*on*down toInvokeModelon the one model - No invocation logging — turn it on for an audit trail
Each fix is checked live against your account by Check my work.
This is your workspace
Sign in and a real, isolated AWS account spins up — the step-by-step guide opens here, graded against your live fixes.
Sign in & launch — freeNo card needed · auto-wiped when you're done