Skip to content

Data Exfiltration from Amazon Kiro via Prompt Injection

mindgard.ai
3 pointscoder-pm2 comments
On HN

Comments

The root cause is simple, the agent could read a live key! It should never have it. It’s a combination of few issues at once: repo read, write access to the settings file and outbound fetch. There is no single way to solve that, this requires egress control and no real secrets! The durable fix means a successful injection cannot extract anything because there is nothing accessible.

It’s all the same for the similar class tools like Cursor, Copilot or Claude Code. Untrusted repos are the new threat model now.

legitimate-data exfiltration gap

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.