Google removed 3 ADK AI workflows after Pillar showed a public GitHub issue could trigger a privileged agent & reach code execution on a CI runner.

Poisoned pull requests contain prompt injection that allows one to control another

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.