Amazon Q Developer Incident

From Indirect Prompt Injection to Host-Level Code Execution

PRIMARY ENTITIES
Amazon Q Developer, AWS
INCIDENT TYPE
Indirect prompt injection / arbitrary command execution
ASSESSMENT
Critical architectural relevance

Executive Summary

In 2025, security researcher Embrace The Red disclosed vulnerabilities in Amazon Q Developer's VS Code extension demonstrating how untrusted content could influence an AI coding agent and cause commands to execute on the developer's host without the expected human confirmation.

The key issue involved commands categorized as effectively "read-only." One of those commands, find, could be abused through command options such as -exec to execute arbitrary commands. An attacker could place malicious instructions in source-code content, causing the AI agent to process those instructions and invoke the command.

The Sandbox Escape

This case is particularly relevant to Opsonance because it shows exactly how an AI-layer manipulation can seamlessly terminate at the operating-system runtime. The vulnerability was fundamentally a failure to restrict the operational behavior of an underlying binary.

AWS subsequently acknowledged the issues in a security bulletin and described fixes that introduced Human-in-the-Loop (HITL) confirmation for the affected commands.

Attack Architecture

The attack path illustrates the progression of an indirect prompt injection turning into a root-level exploit.

THE ATTACK CHAIN
UNTRUSTED FILE
↓
INDIRECT PROMPT INJECTION
↓
AI AGENT CONTEXT
↓
AGENT TOOL SELECTION
↓
"READ-ONLY" COMMAND
↓
COMMAND OPTION ABUSE
↓
ARBITRARY COMMAND EXECUTION
↓
HOST COMPROMISE

The critical transition demonstrated here is: Untrusted data → Model instruction → Tool invocation → Operating-system execution.

Why the Vulnerability Was Significant

The underlying command (find) was not inherently malicious. The problem was the security classification of the tool invocation.

The security model effectively assumed:

find = read-only

But the reality of Linux binaries is:

find + -exec = arbitrary code execution

Therefore, the security boundary was being defined at the level of the command name rather than the effective behavior of the command. That is a classic security-design problem.

Exploitation Conditions

The disclosed research demonstrated that malicious instructions could be embedded inside standard source-code files. When the developer asked Amazon Q to process that file (for example, to summarize or refactor the code), the agent implicitly interpreted the injected instructions and invoked the vulnerable command path.

The researcher successfully demonstrated the possibility of downloading and executing additional payloads and connecting the compromised host to an external command-and-control server.

AWS later stated that the affected Amazon Q configurations involved commands such as find, grep, and echo executing without Human-in-the-Loop confirmation under these conditions. AWS subsequently released fixes requiring explicit confirmation for those specific commands.

Analyst Assessment

The deeper, fundamental problem exposed here is semantic trust transfer.

The system moved progressively through three stages without maintaining a sufficiently strong security boundary between them:

UNTRUSTED DATA
→
TRUSTED AGENT CONTEXT
→
TRUSTED HOST EXECUTION

This is the fundamental pattern of modern AI exploitation: Data becomes instructions, instructions become tool calls, and tool calls become operating-system actions. This pattern is virtually guaranteed to recur across autonomous coding systems.

Opsonance Point of View

This incident is one of the strongest cases for Opsonance's runtime-centric model.

The AI layer can, and will, be manipulated. The runtime, however, does not need to determine whether the prompt was malicious. It only needs to observe the resulting physical behavior of the process.

OBSERVABLE KERNEL PRIMITIVES
  • Process spawning an unexpected shell
  • Unexpected process execution trees
  • Unauthorized filesystem access
  • Establishing unapproved network connections
  • Modifying critical configuration files
  • Attempting to establish persistence

The security decision can therefore be made based on what the agent actually does, rather than what the agent was supposed to do.

DEFENSE-IN-DEPTH ARCHITECTURE
AI SAFETY
(Prompt / Model Controls)
↓
AGENT TOOL POLICY
↓
OPSONANCE RUNTIME DEFENSE
↓
LINUX HOST

AWS's remediation—adding stronger HITL requirements and execution-policy controls—addresses the agent/tool boundary. Opsonance's architectural interest lies one critical layer below that: independent runtime observation and enforcement.

Key Finding

CONCLUSION

Amazon Q demonstrates that prompt injection becomes substantially more dangerous when an AI agent has direct access to operating-system primitives. The critical security boundary is therefore not only: "Can the model understand malicious instructions?" It is definitively: "What can the resulting process actually execute?"

References