Severity

high

Exposure

4/5

Date of incident

April 30, 2024
Amazon Q VSCode Data Exposure

confirmed

Tier -

A

IDE agent read workspace files without scoped execution boundary on file tools.
What Happened

IDE-embedded agent extension processed local workspace files; misconfiguration class allowed broader file reads than users expected during code generation.

Sumarry

AWS disclosed an Amazon Q Developer IDE extension issue that could expose workspace context beyond intended scope.

Detect

NHIM-014 secret-in-env patterns + workspace scope audit

What Happened

Trust Vault mask before model ingress; scope tool read paths

Blekline //

Mask secrets at ingress + scope file tools

Without agent boundary //

Repo secret scanning runs post-commit — after model already saw files

Financial services AI security use case

Looking to integrate AI company-wide?