AnalysisCybersecurityAugust 4, 2026

Gemini Agent-to-Agent Attack Exposed Secrets, Enabled Pull Request Tampering

Pillar Security found that a crafted prompt to a low-privileged Google ADK agent could pass a malicious hand-off comment to a privileged agent, triggering gemini-invoke and granting access to every bash command plus the bot's GitHub token. The researcher could then tamper with PRs, dismiss reviews, and poison the pull-request approval lifecycle in google/adk-python.

Featured · Dan Lisichkin

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
Gemini Agent-to-Agent Attack Exposed Secrets, Enabled Pull Request Tampering — AIBriefs