Pillar Security found a prompt injection attack that lets a public AI agent compromise a privileged one in Google's gemini-cli, leaking GitHub

Poisoned pull requests contain prompt injection that allows one to control another

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.