Mark RadarMARK RADAR
About
EN
Sign in

Google Removes Three ADK Workflows After Agent-to-Agent Attack

1 reports · First detected 2026-08-11 · Last active 2026-08-11

Google’s Agent Development Kit (ADK) is an open-source framework for building and orchestrating AI agents, including systems powered by Gemini. Its Python repository used AI workflows to analyze public GitHub issues, propose code fixes and open pull requests. Pillar Security found that the setup allowed a low-trust, public-facing agent to speak through a trusted bot identity and activate a more privileged agent, exposing a new form of agent-to-agent privilege escalation in software development pipelines.

Pillar showed that a malicious issue could prompt the analysis agent to post “/adk-issue-fix” as adk-bot, satisfying a collaborator check and launching a workflow with repository write access. Researchers demonstrated code execution on a CI runner and exposure of a personal access token, Google API key and Google Cloud service-account credential. Google removed three workflows in a patch carrying a June 9 author date and confirmed the fix on July 21. No in-the-wild exploitation or compromised ADK release was identified in the August 4 report.

All Coverage

1 original reports

The Backstory

The history behind this event
Google Fixes First Known Agent-to-Agent Flaw in AI Toolkit2026-08-08 · 1 reports · similarity 0.80

Companies are rapidly deploying AI agents that can communicate, delegate tasks and access corporate systems, often with sharply different permission levels. Pillar Security said that architecture creates a new attack path: an adversary can compromise a low-privilege agent and exploit trusted agent-to-agent communications to induce a more powerful agent to act. The finding matters because conventional access controls may overlook how authority is transferred across autonomous systems.

Pillar Security recently disclosed what it described as the first known agent-to-agent attack vulnerability in Google’s AI agent development toolkit. A malicious prompt could manipulate a low-privilege agent, which could then trigger a high-privilege agent to execute unauthorized commands. Google has patched the flaw. No precise disclosure date, confirmed victim count or financial loss was reported, while security experts urged companies to include agent permissions and inter-agent trust relationships in their threat models.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)