Google has fixed the issues, which exploited a trust boundary between two AI agents with different privileges to potentially compromise the supply chain.

Poisoned pull requests contain prompt injection that allows one to control another

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.