{
  "id": 105544,
  "title": "Google dev kit spurs first-ever agent-on-agent violence",
  "url": "https://urgent.news/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence-105544",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-03T20:30:37.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496"
  },
  "original_language": "en",
  "account": "Google's Agent Development Kit (ADK) for Python has unveiled a new vulnerability that allows for agent-to-agent exploitation, potentially compromising supply chains. This discovery marks the first-ever real-world example of such an exploit. Researchers from Pillar Security uncovered the issue in the open-source Python toolkit behind Google's ADK, which boasts over 90 million downloads and is used to build and deploy AI agents.\n\nThe problem lies in the way the repository runs two classes of automated AI agents with differing privilege levels that inadvertently share a trust boundary. One agent is low-privileged and public-facing, while the other is high-privileged and accessible only to maintainers. Pillar's Dan Lisichkin found that the low-privileged agent could be manipulated through prompt injection, triggering the higher-privileged agent to execute malicious actions.\n\nTo execute this attack, an external user would need to create a new pull request (PR) containing both legitimate code and malicious elements. The public-facing agent, tied to a high-privileged collaborator's personal access token, would read the PR and mark it for review. This would enable the malicious code to trigger a gated workflow, ultimately allowing the attacker to execute their malicious action within the privileged agent's workflow.\n\nGoogle has since patched the underlying issue, but deemed the exploit non-rewardable due to its reliance on social engineering. Nonetheless, Lisichkin emphasizes that the findings highlight the risks of using AI agents in CI/CD workflows for tasks like triage, pull request reviews, and discussions. He advises security professionals to begin threat modeling these scenarios and understanding the potential blast radius.",
  "summary": "Poisoned pull requests contain prompt injection that allows one to control another",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Google dev kit spurs first-ever agent-on-agent violence",
        "url": "https://urgent.news/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence",
        "published": "2026-08-03T20:30:37.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}