hacker-news · Crawled Aug 4, 2026

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Read original article ↗

AI Summary

Google removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security demonstrated a supply chain attack vector. A malicious GitHub issue could trigger a prompt injection in a triage agent, leading to execution of a privileged code-fixing agent via a trusted bot account. This allowed arbitrary code execution on the CI runner and exfiltration of sensitive credentials, including a bot personal access token (PAT), a Google API key, and a Google Cloud service-account credential. Although no in-the-wild exploitation was observed, the attack chain exploited overly broad permissions and insufficient isolation between automation components.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.