BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Google deletes AI agent workflows after prompt injection attack

Pillar Security researchers demonstrated prompt injection via GitHub issue achieving code execution on ADK runner.

  • Pillar Security discovered a prompt-injection attack that could trick Google’s ADK triage agent into triggering a privileged code-fixing workflow.
  • By exploiting a public GitHub issue, researchers achieved arbitrary code execution on the CI runner and exfiltrated a bot personal access token.
  • Google deleted three vulnerable workflows from its ADK Python repository after the disclosure; no in-the-wild exploitation has been confirmed.
  • The attack chain bypassed an owner/member/collaborator gate by using the trusted adk-bot identity, exposing Google Cloud credentials.

Pillar Security researchers demonstrated that a public GitHub issue could prompt-inject Google’s Antigravity coding agent into posting /adk-issue-fix as the trusted adk-bot account. The issue-analyze.yml workflow automatically analyzed opened issues and posted comments using the bot’s personal access token. That token satisfied the authorization gate for the separate issue-fix.yml workflow, which restricted execution to owners, members, or collaborators.

- Advertisement -

The triage workflow provided the agent with a Google API key and a Google Cloud service-account credential. Because the agent operated under the bot’s identity, an attacker could manipulate it into issuing the privileged command. Consequently, the researchers achieved arbitrary code execution on the CI runner and exfiltrated the bot PAT, as detailed in Pillar’s report.

The runner script restricted allowed commands to gh or git as the first token, but it enabled all Antigravity SDK tools, including file writes. The agent could write a payload and then use Git’s core.hooksPath, as described in Git documentation, to execute arbitrary code through a custom hook.

Google removed issue-analyze.yml, issue-fix.yml, and pr-analyze.yml in a patch dated June 9, 2026. Pillar confirmed the workflows were absent on July 2, and Google acknowledged the fix on July 21. The exposed component was the repository automation, not the distributed ADK Python package itself.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tom Lee: 30% Q3 earnings growth, S&P 8,200+, Bitcoin $100k

Fundstrat’s Tom Lee expects the 10-year Treasury yield to fall below 5% within six...

Bitcoin Eyes Key $87,570 Level as 2026 Candle Nears Green

Bitcoin bulls briefly revisited $87,000, but the 2026 yearly open at $87,570 continues to...

Citrix NetScaler Zero-Day Exploited in Targeted Attacks

Citrix released security updates for CVE-2026-88779, a high-severity memory overflow flaw in NetScaler ADC...

US debt crisis slowly squeezes budget as interest hits $1.1T

The US debt crisis may be unfolding as a slow squeeze, with servicing costs...

Zcash’s NU7 live on testnet as November mainnet nears target

ZCash activated NU7 upgrade on testnet on October 4 at block 4,465,026.NU7 aims to...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading