Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS THREAT INTELLIGENCE CYBER RISK CYBERATTACKS & DATA BREACHES NEWS Flaws in Google APK for Python Unlock Agent-to-Agent Attack Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. Elizabeth Montalbano,Contributing Writer August 5, 2026 4 Min Read SOURCE: BRAIN LIGHT VIA ALAMY STOCK PHOTO AI agents can be weaponized against each other using prompt injections via a chain of flaws in Google's open source Agent Development Kit (ADK) for Python, potentially disrupting the software supply chain and demonstrating yet another new attack vector introduced by the emerging technology. Researchers from Pillar Security discovered the flaws, present in the ADK's adk-python repository, which allowed a low-privileged, public-facing agent in a workflow to trigger commands that could be executed by a high-privileged one, according a report published on Aug. 4. This means that potentially malicious, untrusted text — such as a pull request or issue — could be performed by a trusted AI agent with repository privileges. LOADING... "Pillar Security researchers have identified the first practical, real-world case of agent-to-agent exploitation in a multi-agent system in a real production environment, a class of attack not seen in real production systems until now," Dan Lisichkin, cybersecurity researcher for Pillar, wrote in the report this week. Related:Attackers Exploit N-able Patch Bypass Flaw on RMM Servers The attack was especially problematic because it relied on prompt injections embedded in GitHub pull requests to exploit a trust boundary between two AI agents with different privilege levels, according to Pillar. In their proof-of-concept (PoC) exploit, the researchers showed that a public-facing AI agent reviewing pull requests could be manipulated into triggering a maintainer-only AI agent capable of performing privileged actions. This created a pathway to approve or execute malicious code in continuous integration (CI)/continuous delivery (CD) workflows that affect the development process and thus the software supply chain, Lisichkin said. This scenario, in which one AI agent can be used to attack another, turned "a benign automation into a path that ends in a potential software supply chain compromise," he wrote. Attack Flow and Remediation LOADING... Google's ADK for Python has been downloaded more than 90 million times and is widely used by developers who work with Gemini, Google's large language model (LLM). Pillar credited Google for a prompt response to the flaws, which were reported in early June and remediated on July 9 and July 21, respectively. Google did not immediately respond to requests for comment by Dark Reading today. Specifically, the researchers showed that a malicious embedded prompt could persuade the agent to publish a specially formatted @gemini-cli command, according to the report. "That comment was then recognized by a dispatcher workflow and routed to a more privileged Gemini-based automation," Lisichkin wrote. Related:'Certighost' Flaw Haunts Microsoft Active Directory Certificates The finding demonstrates how interactions between AI agents are now emerging as a new privilege-escalation attack surface. Pillar's discovery comes hot on the heels of the emergence of autonomous LLM attacks, introducing yet another threat type against which defenders need to secure AI agents and systems. While the flaws were characterized as a prompt injection issue — a common attack vector for LLMs and AI agents — the real issue it created for how organizations are using AI agents "is delegation," says Ryan McCurdy, vice president of marketing at database governance firm Liquibase. “Enterprises are starting to put multiple AI agents into software delivery with different tools, permissions, and levels of authority," he says. "This research shows why governing each agent independently isn't enough. Organizations also have to understand what one agent can cause another agent to do." The flaws demonstrated a new security consideration for enterprises when developing AI agent behavior, McCurdy says, because "a low-privileged agent shouldn't be able to use a higher-privileged agent to get around controls it couldn't bypass on its own." Securing Agents Going Forward The bigger takeaway from the discovery of the flaws is that AI agents are changing some of the assumptions security teams have relied on for years, Pillar's Lisichkin said. In the past, a system was generally considered safe if only trusted or privileged users could reach it. But an AI agent that reads untrusted content and has access to credentials can become a bridge into more sensitive systems. Related:Vatican's Official Prayer App Leaks 700K+ Global Users' PII "The compromise lived in the seams, in one agent's ability to reach across a privilege boundary and set another in motion, and in the gap between what each permission looks like it can do and what it can actually do when an adversary chains it with the others," he wrote. "Threat models built around individual components miss this entirely. The edges between agents, the delegation, the impersonation, the triggering, are now first-class parts of the attack surface and have to be modeled as such." For CISOs and security teams, this means they first must understand where agentic workflows are already operating — especially those that process untrusted content such as pull requests, issues, tickets, emails, or support chats while also holding credentials, Lisichkin said. To create better defenses, organizations should assume that these agents can potentially be influenced by attackers and constrict their tools and permissions, provide their own identities, and limit their scopes rather than give them broad access tied to human accounts or long-lived credentials, he said. Lisichkin added that organizations also should ensure a lower-privileged agent cannot activate a more privileged one without an authorization check that can't be faked by a prompt injection. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos More Webinars You May Also Like VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 VULNERABILITIES & THREATS 'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails by Nate Nelson SEP 19, 2025 Black Hat USA Coverage APPLICATION SECURITY AI Harnesses Burst With Potential Exploit Opps byRobert Lemos JUL 30, 2026 4 MIN READ CYBERSECURITY OPERATIONS Red Agents vs. Blue Agents: How to Make AI Better at Defense byRob Wright JUL 29, 2026 5 MIN READ APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector byEricka Chickowski JUL 29, 2026 5 MIN READ СLOUD SECURITY Ghost Credentials Expose Cloud Systems to Hidden Identity Risks byJeffrey Schwartz JUL 28, 2026 3 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices