dotsagent.io
Language:English
CVE-2025-8217

Amazon Q Developer extension shipped with a wiper prompt

Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.

What happened

AWS security bulletin AWS-2025-015, dated 23 July 2025, reports that version 1.84.0 of the Amazon Q Developer extension for VS Code shipped with an injected wiper prompt. The prompt invoked q --trust-all-tools --no-interactive, which lets the agent use every tool without asking first.

AWS traced the root cause to a GitHub token in CodeBuild that had broader permissions than the build needed. The issue is tracked as CVE-2025-8217.

Why it worked

A build token with too much access made the release pipeline the attack surface. Once the prompt was inside the extension, the flags it used switched off confirmation, so nothing stood between the instruction and the tools.

What to do

  • Scope CI and build tokens to the single repository and permission each job needs.
  • Require review before anything lands in a release branch.
  • Never run agents with --trust-all-tools or non-interactive flags on machines that hold real data.
  • Keep tool approval switched on for destructive commands.

Use least-privilege credentialsRequire approval for consequential actionsVet skills, plugins and MCP servers

Work through the security checklist →

Sources

  1. aws.amazon.com/security/security-bulletins/AWS-2025-015/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026