Google ADK Flaws Reveal What Happens when AI Agents Trust the Wrong Message
9 Articles
9 Articles
Google ADK flaws reveal what happens when AI agents trust the wrong message
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed pull requests submitted by external contributors. The agent posted its res…
Google dev kit spurs first-ever agent-on-agent violence
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source P…
Researchers have demonstrated the very first attack agent against agent in real conditions, exploiting a flaw in Google's IA agent development kit for Python. Summer 2026 is decidedly loaded for the security of artificial intelligence agents. After OpenAI, whose agent hacked
Google has released the Agent Development Kit (ADK), an agent development framework that supports enterprise-scale development. Security firm Pillar has discovered a vulnerability in this ADK that allows for attacks that "hack low-privilege agents and execute code with higher privileges." Read more...
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






