Google ADK Flaws Enable High‑Privilege AI Agent Actions
Security vulnerabilities in the Google Agent Development Kit (ADK) Python GitHub repository allowed public AI agents to trick automated workflows into performing high-privilege actions, including modifying pull requests and exposing credentials. Researchers from Pillar Security demonstrated multiple exploitation paths — a triage agent manipulated via crafted pull requests and prompt injection in public issues causing an analysis agent to run privileged fixing workflows. During testing, attackers could obtain a personal access token and a Google Cloud service account key. Google removed the problematic workflows in early July 2026 and deployed fixes for the remaining issue later that month after Pillar Security reported the findings.
- •Security vulnerabilities were discovered in the GitHub repository for the Google Agent Development Kit (ADK) for Python.
- •Flaws allowed external contributors to manipulate automated agents to modify issues, pull requests, and provide fake approvals.
- •Pillar Security researchers demonstrated exploit chains including prompt injection and malicious pull-request instructions.
