Google ADK Agent-to-Agent Attack: Privilege Boundary Breakdown Calling Privileged CI...

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.

A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning.