www.pillar.security
Agent-to-Agent Exploitation Discovered in Google's ADK Repository
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Pillar Security researchers identified a novel agent-to-agent exploitation method in Google's ADK repository, specifically in the google/adk-python toolkit. This vulnerability allows a low-privileged AI agent to manipulate a high-privileged agent, potentially leading to software supply chain compromises. The exploit leverages prompt injection through poisoned pull requests, which can trigger actions by the more privileged agent. Google has since mitigated the issue but deemed it non-rewardable due to its reliance on social engineering. This incident highlights the evolving threat landscape in CI/CD environments where AI agents operate. Security practitioners are urged to reevaluate threat models to account for such scenarios. The findings will be presented at DEF CON's AI Village on August 7, 2026.
Key Points: • First documented case of agent-to-agent exploitation in a production environment. • Vulnerability allows low-privileged agents to control high-privileged agents via prompt injection. • Google has mitigated the issue but considers it non-rewardable due to social engineering aspects.