Tag: ADK AI Workflows

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
News

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Three AI agent workflows were removed from Google's Python repository for the Agent Development Kit (ADK). A public GitHub issue could be used to trick a triage agent into activating a privileged code-fixing agent, as demonstrated by Pillar Security. The public agent might be prompt-injected to post /adk-issue-fix as adk-bot, according to the researchers. The comment satisfied the owner, member, or collaborator gate of the privileged workflow since they recognized the bot as a collaborator. The permission bridge was created using the trusted bot identity. The group showed how to exfiltrate the bot's personal access token (PAT) and execute arbitrary code on the continuous integration (CI) runner. Additionally, the privileged job had a Google Cloud service-account login and a Google A...