Gemini Agent-to-Agent Attack Exposed Secrets, Enabled Pull Request Tampering

Pillar Security found that a crafted prompt to a low-privileged Google ADK agent could pass a malicious hand-off comment to a privileged agent, triggering gemini-invoke and granting access to every bash command plus the bot's GitHub token. The researcher could then tamper with PRs, dismiss reviews, and poison the pull-request approval lifecycle in google/adk-python.
Featured · Dan Lisichkin
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Z.ai CEO Jie Tang: GLM 5.3 gains come from RL, not parameter count
- New tool adds 14 skills to Claude Code and Cursor for Markdown diagrams
- Tool turns Claude into a team of AI employees on your Mac
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills