Severity

high

Exposure

4/5

Date of incident

April 30, 2024
Amazon Q VSCode Data Exposure

confirmed

Tier -

A

IDE agent read workspace files without scoped execution boundary on file tools.
What Happened
IDE-embedded agent extension processed local workspace files; misconfiguration class allowed broader file reads than users expected during code generation.
Sumarry
AWS disclosed an Amazon Q Developer IDE extension issue that could expose workspace context beyond intended scope.
Detect
NHIM-014 secret-in-env patterns + workspace scope audit
What Happened
Trust Vault mask before model ingress; scope tool read paths
Blekline //
Mask secrets at ingress + scope file tools
Without agent boundary //
Repo secret scanning runs post-commit — after model already saw files

Looking to integrate AI company-wide?