← All articles

Malicious repository content can make Amazon's Kiro AI IDE leak local data

Researchers showed that Amazon Kiro, an AI-powered agentic development environment, can be turned against its user through prompt injection. Attacker-controlled content in a repository the developer opens can steer the Kiro agent into transmitting sensitive local information to an external server, abusing a feature called Kiro Powers that bundles model context protocol server configurations, steering files, and hooks. The developer only has to open the workspace and interact with the agent. It is part of a wider run of similar flaws in AI coding tools, where untrusted content or links quietly redirect an agent into exfiltrating data or executing code without any approval prompt. Updating the tool addresses the reported issue.

Check
Update Kiro to the latest version, and treat opening untrusted repositories in any agentic AI development environment as risky, since hidden instructions can drive the agent without an approval prompt.
Affected
Developers using Amazon Kiro or similar agentic AI IDEs who open untrusted repositories; malicious content can prompt-inject the agent to exfiltrate local data or alter its own tool and context configuration files.
Fix
Keep agentic IDEs updated, review model context protocol configs and steering files for tampering, limit what secrets and paths the agent can reach, and avoid opening untrusted projects in autonomous tools.