August 5, 2026
- Google pulled three ADK agent workflows after an agent-on-agent prompt injection. Pillar Security showed that a crafted public GitHub issue could manipulate a low-privilege triage agent in Google's
adk-pythonAgent Development Kit into posting/adk-issue-fixasadk-bot, satisfying the collaborator check needed to trigger a privileged code-fixing agent — a hand-off that could tamper with pull requests, expose secrets, and enable supply-chain compromise (The Hacker News, SecurityWeek). The Register calls it the first real-world "agent-on-agent" exploit (The Register). · AI & Model Security
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing