{"rewrite":{"id":"r_4c93b9c5ed6f3335066850ca","clusterId":"c_a421e40599863c441479e252","slug":"google-adk-flaw-lets-low-privilege-agents-run-maintainer-only-workflows","model":"deepseek-v4-flash:free","headline":"Google ADK Flaw Lets Low-Privilege Agents Run Maintainer-Only Workflows","summary":"Security firm Pillar found a vulnerability in Google's Agent Development Kit that lets an attacker prompt-inject a low-privilege agent into invoking maintainer-only workflows. The agent can impersonate a maintainer with authority to approve or reject pull requests. Google has implemented mitigation measures after Pillar reported the issue.","whyItMatters":"The attack shows agent-to-agent privilege boundaries fail in CI/CD settings, creating new attack surfaces that current threat models do not cover.","webCardHtml":"\u003cp\u003ePillar\u0026#39;s proof of concept starts with a pull request containing a crafted prompt. The agent, designed to comment only on specified content, outputs arbitrary text and is treated by GitHub as a collaborator rather than a bot, which lets it call maintainer-only workflows.\u003c/p\u003e\u003cp\u003eBy building the malicious prompt to match Google\u0026#39;s official contribution guide, Pillar moved from a low-privilege agent to a maintainer-level one that can reject or approve pull requests. Google has already rolled out mitigations.\u003c/p\u003e","blueskyPost":"Pillar found a Google ADK flaw where prompt injection lets a low-privilege agent invoke maintainer-only workflows and impersonate a pull request approver. Google has patched it.","twitterPost":"Pillar discovered a Google ADK vulnerability: prompt injection lets low-privilege agents trigger maintainer-only workflows and impersonate approvers. Google has mitigated.","threadsPost":null,"newsletterBlurb":"Security firm Pillar demonstrated a prompt injection attack on Google's Agent Development Kit that escalates a low-privilege agent to maintainer-level authority in CI/CD. Google has implemented mitigations.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260804-agent-development-kit-attack/\",\"title\":\"Hacking Technique Found in Google ADK That 'Hacks Low-Privilege Agents to Execute Code with Higher Privileges'\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4628,"outputTokens":463,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1786323279,"createdAt":"2026-08-10T00:48:57.000Z","publishedAt":"2026-08-10T00:51:44.000Z","updatedAt":"2026-08-10T00:48:57.000Z"},"cluster":{"id":"c_a421e40599863c441479e252","canonicalTitle":"「権限の低いエージェントをハックして上位権限でコードを実行する」というGoogle ADKのハッキング手法が発見される","representativeArticleId":"a_785d9fea04761493c9814885","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-04T14:00:00.000Z","lastSeenAt":"2026-08-04T14:00:00.000Z","updatedAt":"2026-08-10T00:51:45.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260804-agent-development-kit-attack/","title":"「権限の低いエージェントをハックして上位権限でコードを実行する」というGoogle ADKのハッキング手法が発見される"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
