The AI IDE That Leaks Without Being Asked
A new Mindguard disclosure against Amazon Kiro turns a routine "open a project, send a message" workflow into silent data exfiltration — through Kiro Powers, the very layer that gives the agent its tools
On Aug 27, The Hacker News published a new vulnerability in Amazon Kiro, AWS's agentic AI IDE, disclosed by Mindguard (researcher Fergal Glynn). Parallel coverage at Cyber Tech World, GuardianMSSP, and ReconBee.
No CVE. Reproduced against Kiro IDE 0.7.45 on Windows (shipping release at disclosure was 1.0.337 — hundreds of point releases newer). AWS updated AWS-2025-019 — the bulletin covering a July 2026 Kiro RCE — to include broader prompt-injection issues across Kiro and Amazon Q Developer, recommending an upgrade of the shared Language Server to the latest build.
What the flaw actually does
Per the Mindguard summary, attacker-controlled repository content can influence the Kiro agent and exfiltrate sensitive local information to an external endpoint. The user has to do two things:
- Open the malicious project via File → Open Workspace From File rather than the folder directly.
- Send any message to the agent.
That is the entire user-side chain. The user never types a malicious prompt or refers to the attacker content. Mindguard reports the flow is reproducible against both trusted and untrusted workspaces, with low exploitation difficulty. Opening a project and sending a message: every AI IDE user does both on the first minute of their workday.
The Kiro Powers substrate
The interesting part is where the payload lives. Kiro Powers bundles MCP server configurations, steering files called POWER.md, hooks, and contextual knowledge. The steering file is an "onboarding manual" giving the agent persistent context — what MCP tools are available and when to use them.
Good design for reproducible workflows. Also a good delivery vehicle: opening a workspace loads Powers, and Powers speaks to the agent with the authority of context, not a user message. The runtime does not have to be tricked into treating attacker text as instructions — the text arrives as what the agent's tools are supposed to be doing.
Same architectural class as the NemoClaw chat-template poisoning we covered Aug 26, transposed from Ollama's chat template onto Kiro's Powers file. The exploited substrate is not the model, not the system prompt, not the user message — it is the configuration layer that joins the agent to its tools, treated as config rather than as a signed, integrity-checked artifact.
Why "no malicious prompt required" matters
A year of prompt-injection findings has trained defenders to watch for the moment a user pastes something suspicious or an agent reads a webpage with visible instructions. Both retain the notion that instructions enter through a channel a human might inspect.
The Mindguard flow removes that. Instructions enter through a project file the agent treats as its own runtime context, opened through the ordinary "open a workspace" gesture. Nothing in the user's message looks wrong. Nothing in the response looks wrong. Exfil happens as a byproduct of the agent using the tool configuration it was handed.
That is the shape defenders now have to plan for on the coding-agent tier: the payload is not in the conversation, it is in the configuration substrate the conversation runs on.
The already-mixed track record on this substrate
Not the first Kiro finding in two months. The July 2026 Intezer disclosure, covered by The Hacker News, showed Kiro's MCP configuration file could be rewritten by a poisoned web page for arbitrary code execution — a full RCE. AWS fixed it in AWS-2025-019 and an updated Kiro build.
The Aug 27 finding is a distinct primitive on the same substrate — the agent's persistent tool-context files — reaching sensitive local data instead of code execution. Two independent vulnerabilities on the same substrate in one summer say "Powers-as-configuration" is the abstraction that keeps producing findings.
Same week, CISA KEV picked up CVE-2026-9198, the unauthenticated RCE in IBM Langflow — another agentic-AI orchestration layer where the exploit walks in through the runtime, not the model.
What defenders can carry away
First, the "open workspace" gesture is a security event. Opening a workspace can push persistent context into the agent's runtime through Powers-style files. A threat model that only guards the chat window is not modeling what reaches the agent.
Second, the configuration substrate needs the same integrity treatment as the model artifact. Signed system prompts, chat templates, and skill/Powers files are the same idea applied to the layer that turns a model into a working agent. Treating that layer as "just config" is the shared design gap between NemoClaw, Kiro Powers, and the cohort OWASP formalized in the Agentic Skills Top 10 v1.0 on Aug 17.
Third, runtime behavioral observation closes the window between vulnerable and fixed. Mindguard's finding has no CVE. Users on Kiro 0.7.45 will not get a scanner ticket. The observable that catches the exploit is the same one that catches its cousins: sensitive local data leaves the agent's process for an endpoint the user never named.
The takeaway
The Kiro Powers disclosure is small — no CVE, one researcher, one press cycle. It matters because it is the second time this quarter a researcher has turned an AI IDE's tool-configuration layer into a data-loss or code-execution primitive without a malicious prompt.
The model is not the boundary being violated. The runtime that ships the agent's tools is. That is where defense-in-depth for coding agents has to live.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.