Severity
Exposure
Date of incident
Amazon Q VSCode Data Exposure
confirmed
Tier -
A
IDE agent read workspace files without scoped execution boundary on file tools.
What Happened
IDE-embedded agent extension processed local workspace files; misconfiguration class allowed broader file reads than users expected during code generation.
Sumarry
AWS disclosed an Amazon Q Developer IDE extension issue that could expose workspace context beyond intended scope.
Detect
NHIM-014 secret-in-env patterns + workspace scope audit
What Happened
Trust Vault mask before model ingress; scope tool read paths
Blekline //
Mask secrets at ingress + scope file tools
Without agent boundary //
Repo secret scanning runs post-commit — after model already saw files
