Google dev kit spurs first-ever agent-on-agent violence
ID: c7f4001f-8cc0-5c6d-91b6-004019b8565c
STIX ID: report--c7f4001f-8cc0-5c6d-91b6-004019b8565c
Feed Name: The Register (Security)
Threat Score
Executive summary: Pillar Security disclosed an "agent-on-agent" exploit in Google's ADK-Python where a public, low-privilege AI triage agent could be prompt-injected to trigger a privileged maintainer agent, allowing an attacker who staged poisoned pull requests to perform malicious actions; Google patched the repository but judged the issue ineligible for a bounty because it required social engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
