What happened
An attacker injects a malicious system prompt into an official extension update, instructing the local agent runtime to execute recursive workspace deletions.
2025-07-28
CriticalPrimaryDeep dive into the July 2025 incident where a malicious system prompt was injected into Amazon Q Developer's official VS Code extension v1.84, triggering workspace deletions.
What happened
An attacker injects a malicious system prompt into an official extension update, instructing the local agent runtime to execute recursive workspace deletions.
Why it matters
AWS reported no customer resource impact. The realized exposure is that an official extension release carried attacker-authored instructions into the agent's system prompt on developer machines.
Missing authorization check
Not applicable: no agent authorization boundary was crossed in this incident.
Would PP block it?
The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.
Incident analysis
2025-07-28
Amazon Q Developer v1.84 published to the VS Code Marketplace carrying the injected system prompt.
2025-07-29
AWS security teams yank v1.84 from the marketplace and release a clean v1.85 rollback version.
Authorization boundary
This incident is categorized as Production deletion. The relevant Permission Protocol gate is Deploy Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.
Start small
This incident maps to Deploy Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.