When the AI Edits Its Own Trust Boundary: Remote Code Execution Vulnerability in AWS’s Agentic IDE

Joint research with Kodem Security. Invisible prompt injection in fetched web content caused Kiro to rewrite ~/.kiro/settings/mcp.json via fsWrite without meaningful approval, then auto-reload and run attacker MCP startup commands. Confirmed on 0.9.2 (macOS) and 0.10.16 (Ubuntu); patched in 0.11.130. AWS assigned no CVE. Reported via HackerOne Feb 11, 2026; third mcp.json trust-boundary class against Kiro since 2025.