Evidence-backed facts
- AgentCore harness tools are declared for the agent and include remote MCP, AgentCore Gateway, browser, code interpreter, and inline client-executed functions. informative
- The allowedTools setting limits tool selection during harness invocation and should expose only the tools needed for the request. informative
- Direct Agent Runtime command execution is a separate API and IAM permission, so restricting model tool selection alone does not prevent that operation. informative