Gemini ADK Under Attack: Two Vulnerabilities Expose the Risks of Automated AI Agents

Two critical vulnerabilities in Google's Gemini ADK allow remote code execution and PR manipulation, highlighting severe supply chain risks for AI agents.

Gemini ADK Under Attack: Two Vulnerabilities Expose the Risks of Automated AI Agents
AI

Illustrative image generated with AI

On August 4, 2026, Pillar Security disclosed two flaws in the google/adk-python repository that show how an attacker can manipulate the pull request lifecycle and achieve remote code execution by jumping from one AI agent to another. The vulnerabilities, reported to Google, affect the Agent Development Kit for Python and the Gemini CLI extension, and highlight the need for privilege isolation between agents with different trust levels.

A prompt chain: from a public comment to command execution

The first flaw exploits communication between a low-privilege AI agent – the one doing PR triage – and high‑privilege maintainer workflows. The triage agent operated with Collaborator permissions and accepted commands from any GitHub user able to comment on a PR.
Simply inserting a comment with the syntax @gemini-cli <prompt> was enough to trigger the gemini_invoke.yml workflow. This exposed tools available through an MCP server, including arbitrary bash command execution.

Anyone could therefore obtain a remote shell in the agent’s context. The next step was immediate: read the process’s GITHUB_TOKEN, a secret with write access to issues, comments, labels and reviews. With that token, an attacker could modify any pull request metadata, approve or dismiss reviews, and invoke further automated workflows – gemini-invoke and gemini-review – on any PR, including malicious ones.

The critical phase, however, remained the actual code merge. That requires a human maintainer’s approval. The researcher built a social engineering scenario: taking advantage of the ability to impersonate other users (writing comments in their name) and simulate a “human” review trail, a maintainer could be led to believe that a PR had already been vetted and legitimately approved.

The second bug: RCE with no human interaction

After the initial report, Pillar Security discovered a second entry point in the Antigravity‑SDK‑based automation, a component of the automatic agent. This vulnerability allowed direct remote code execution without the need to trick any maintainer.
No technical details were disclosed, but the severity was rated critical: an attacker could obtain a shell in the repository’s context without going through the PR interface and with zero human interaction.

Google acknowledged the first flaw as not eligible for a bug bounty because a malicious merge still required a human step. The second, however, prompted the company to rapidly fix the issue and strengthen privilege separation between agents.

Why these vulnerabilities are a supply chain problem

Gaining an unauthorized merge on a repository like google/adk-python would have allowed injecting malicious code into the development kit used by thousands of Python projects. A successful attack could have:

  • Poisoned build pipelines and development environments.
  • Exfiltrated secrets from other repositories that depend on ADK.
  • Extended compromise to internal Google services through linked tokens and workflows.

Even though the full exploit still required deceiving a maintainer, PR manipulation capabilities were sufficient to build a credible scenario. The second bug, on the other hand, eliminated the need for human interaction entirely.

What Google did and what developers need to do

After the initial report, Google applied hardening to privilege separation between agents. The second vulnerability was fixed without further public details. No CVE has been assigned.

One clear lesson remains: giving an AI agent access to tokens with write powers is a risk. Suggested mitigations include:

  • Limit agent privileges to the bare minimum.
  • Never expose tokens or secrets directly to automated workflows.
  • Monitor interactions between agents with different roles, especially if one of them accepts unauthenticated commands.
  • Treat any input coming from an external agent as untrusted, even if it originates from your own CI/CD ecosystem.

The agent‑to‑agent attack described by Pillar Security is not just a Google problem: it is a pattern that could repeat in any repository using AI bots with tiered privileges. As automation grows in development pipelines, the attack surface widens – and isolating trust becomes the ultimate line of defense.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →