But you have to put them somewhere; how is idk, AWS credential management secured?
If someone gains access to a system that uses the credentials, then there is, in principle, no difference between puppeteering that system versus stealing its credentials.