A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning.

Poisoned pull requests contain prompt injection that allows one to control another

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.