It makes sense for a personal project. The fix should be accomplished as a standalone role or scoped credential per user. Once this is done the prefix will be a real boundary, not just a name. Good luck with that, nice project!
Good news, I've done the fix. Each listed principal now gets its own plane at deploy time. Now we have dedicated AgentCore runtime locked to its owner via resource policy, dedicated execution role confined to its storage trees via bucket policy