Google ADK for Python: A Chain of Vulnerabilities Enables Attacks Between AI Agents
Discover how a chain of vulnerabilities in Google ADK for Python enables attacks between AI agents, affecting GitHub and CI/CD pipelines.
Illustrative image generated with AI
GitHub prompt injection targeting agents with different privilege levels
Pillar Security identified a chain of vulnerabilities in Google’s Agent Development Kit (ADK) for Python, distributed through the adk-python repository.
The attack begins with a pull request or GitHub issue containing manipulated instructions. A public agent with limited privileges can use them to influence an internal agent responsible for maintenance.
The second agent, equipped with broader permissions, can then be tricked into performing unauthorized operations. The underlying issue is therefore not limited to the contents of a single prompt injection, but also involves automated delegation between agents with different levels of trust.
The risk to Gemini, GitHub, and CI/CD pipelines
The vulnerability affects scenarios that combine ADK with Gemini, Gemini CLI, GitHub workflows, and CI/CD automation. The package has surpassed 90 million downloads.
In an exposed environment, the chain could facilitate:
- indirect privilege escalation between agents;
- approval or publication of unauthorized changes;
- execution of malicious code in pipelines;
- software supply chain compromise.
A public agent does not necessarily need to obtain administrative privileges directly: it can use the internal agent as an operational intermediary.
Pillar Security reported the flaws to Google in early June. The research was made public on August 4. The source does not provide a CVSS score or CVE identifiers.
Fixes and safeguards for ADK environments
Google fixed the vulnerabilities on July 9 and July 21. ADK users should update the package to the patched versions and also review the dependencies used by their projects.
The main countermeasures include:
- strictly isolating public agents from privileged agents;
- preventing untrusted inputs from generating operational commands;
- requiring manual approval before triggering sensitive workflows;
- monitoring and validating GitHub events;
- applying the principle of least privilege to CI/CD pipelines.
Role separation must be accompanied by controls over delegated actions: a privileged agent should not automatically treat instructions originating from public content as trusted.
Sources
This article is an original reworking based on the sources below.




