Google ADK security flaws let attackers hijack AI agent workflows via prompt injection
Security researchers at Pillar Security discovered vulnerabilities in the GitHub repository of Google's Agent Development Kit for Python that allowed unauthorized, high-privilege automation. Attackers could embed malicious instructions inside pull requests or public issues to trick AI triage and analysis agents into triggering restricted workflows. During testing, researchers successfully extracted a personal access token and accessed a Google Cloud service account key from an external server. Google was notified and removed the affected workflows in early July, completing fixes for a second related flaw later that month. The findings highlight a broader security challenge in multi-agent systems, where authority passed through natural language can blur permission boundaries between low- and high-level automated processes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in