---
title: "Amazon Q Developer 扩展中包含擦除数据的提示词 · DotsAgent"
description: "VS Code 版 Amazon Q Developer 1.84.0 随附了一个旨在擦除数据的注入提示词。AWS 将问题追溯到 CodeBuild 中权限范围过大的 GitHub token。"
url: https://dotsagent.io/zh/security/incidents/2025-07-amazon-q-wiper-prompt
---

2025年7月23日

CVE-2025-8217

# Amazon Q Developer 扩展中包含擦除数据的提示词

VS Code 版 Amazon Q Developer 1.84.0 随附了一个旨在擦除数据的注入提示词。AWS 将问题追溯到 CodeBuild 中权限范围过大的 GitHub token。

## 事件经过

AWS 安全公告 AWS-2025-015（日期为 23 July 2025）指出，VS Code 版 Amazon Q Developer 扩展的 1.84.0 版本随附了一个注入的擦除数据提示词。该提示词调用 q --trust-all-tools --no-interactive，使 agent 无需事先确认即可使用所有工具。

AWS 将根本原因追溯到 CodeBuild 中的一个 GitHub token，其权限超出了构建所需范围。该问题编号为 CVE-2025-8217。

## 攻击奏效的原因

权限过大的构建 token 使发布流水线成为攻击面。提示词一旦进入扩展，其中使用的 flags 就会关闭确认机制，因此指令可以直接调用工具。

## 应对措施

- 将 CI 和构建 token 的权限限制在每项任务所需的单个 repository 和权限范围内。
- 任何内容合并到发布分支前都必须经过审核。
- 切勿在存有真实数据的机器上使用 --trust-all-tools 或非交互 flags 运行 agent。
- 执行破坏性命令时，始终开启工具审批。

[使用最小权限凭据](https://dotsagent.io/zh/security#leastPrivilege)[重大操作须经人工批准](https://dotsagent.io/zh/security#humanApproval)[审查技能、插件和 MCP 服务器](https://dotsagent.io/zh/security#supplyChainVetting)

- [postmark-mcp：恶意 MCP 服务器暗中复制所有邮件](https://dotsagent.io/zh/security/incidents/2025-09-postmark-mcp-backdoor)

- [mcp-remote 通过 authorization_endpoint 注入 OS 命令](https://dotsagent.io/zh/security/incidents/2025-07-mcp-remote-os-command-injection)

[查看安全检查清单 →](https://dotsagent.io/zh/security/checklist)

## 来源

1. [aws.amazon.com](https://aws.amazon.com/security/security-bulletins/AWS-2025-015/)/security/security-bulletins/AWS-2025-015/

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
