Published August 3, 2026 · Added August 3, 2026

I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository

Pillar Security says Google's open-source ADK Python repository exposed CI/CD agent workflows to prompt-injection attacks from malicious pull requests, letting one agent influence a more privileged agent before Google hardened the project.

Pillar Security says Google’s open-source ADK Python repository exposed CI/CD agent workflows to prompt-injection attacks from malicious pull requests, letting one agent influence a more privileged agent before Google hardened the project.

Read the original story.

Source: Pillar