CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3803

As cited

Copy frozen at (site build).

ai security

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after security researchers demonstrated that a public GitHub issue could be manipulated to trigger a privileged code-fixing agent. Pillar Security identified a prompt injection vulnerability that allowed attackers to exploit a triage agent into executing elevated commands through the adk-bot collaborator account.

Why it matters: Organizations using Google's ADK or deploying AI agents in collaborative environments face supply chain and privilege escalation risks; practitioners should audit AI agent workflows for prompt injection vectors and restrict bot permissions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google removed three artificial intelligence (AI) agent workflows from its Agent Development Kit repository after Pillar Security revealed that a public GitHub issue could be manipulated to trigger a privileged code-fixing agent. The vulnerability allowed an attacker to inject prompts into a triage agent, which would then execute sensitive operations as an authorized bot user.

Why it matters: Development teams using ADK are exposed to privilege escalation attacks through prompt injection on public issues; removing these workflows closes the attack path but practitioners should review their own AI agent orchestration for similar trust boundaries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google removed three artificial intelligence (AI) agent workflows from its Agent Development Kit repository after Pillar Security revealed that a public GitHub issue could be manipulated to trigger a privileged code-fixing agent. The vulnerability allowed an attacker to inject prompts into a triage agent, which would then execute sensitive operations as an authorized bot user.

Why it matters: Development teams using ADK are exposed to privilege escalation attacks through prompt injection on public issues; removing these workflows closes the attack path but practitioners should review their own AI agent orchestration for similar trust boundaries.

VendorsGoogleGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary