AI agent flaws in AWS, Google, and Vercel let forged tool calls reach tools without model authorization, while several paths skip the model entirely.

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.

Security vulnerabilities discovered in the GitHub repository for the Google Agent Development Kit for...