Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

Google ADK Flaw Lets Low-Privilege Agents Run Maintainer-Only Workflows

The attack shows agent-to-agent privilege boundaries fail in CI/CD settings, creating new attack surfaces that current threat models do not cover.

Reporting from 1 source: GIGAZINE.

Google ADK Flaw Lets Low-Privilege Agents Run Maintainer-Only Workflows

Security firm Pillar found a vulnerability in Google's Agent Development Kit that lets an attacker prompt-inject a low-privilege agent into invoking maintainer-only workflows. The agent can impersonate a maintainer with authority to approve or reject pull requests. Google has implemented mitigation measures after Pillar reported the issue.

Pillar's proof of concept starts with a pull request containing a crafted prompt. The agent, designed to comment only on specified content, outputs arbitrary text and is treated by GitHub as a collaborator rather than a bot, which lets it call maintainer-only workflows.

By building the malicious prompt to match Google's official contribution guide, Pillar moved from a low-privilege agent to a maintainer-level one that can reject or approve pull requests. Google has already rolled out mitigations.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources