A malicious GitHub issue could make a low-privilege ADK agent trigger a maintainer-privileged one (agent-to-agent escalation)
2026-google-adk-agent-privilege-escalation · 2026-08-03
Researchers showed that GitHub Actions workflows in Google's open-source Agent Development Kit (ADK) for Python could be chained: a public, low-privilege triage agent was prompt-injected via a crafted issue into triggering a maintainer-only agent holding broad repository and cloud credentials, achieving code execution on the CI runner and exposing its secrets. Google removed three workflows.
System
- Framework
- Google Agent Development Kit (ADK) for Python — GitHub Actions agent workflows
- Tools
- github-actions, ci
- Vendor
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → multi-agent-failure/cascade → unsafe-action/unauthorized-write
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
An unprivileged party opened a crafted GitHub issue that prompt-injected the repository's public, low-privilege triage agent. That agent's output became the injection vector for a second, maintainer-only agent with broad repository and cloud credentials, which then executed attacker-controlled commands on the CI runner.
Root cause
A low-privilege agent acting on untrusted issue content could influence a higher-privilege agent, crossing a privilege boundary. Trust flowed from an untrusted, public entry point through one agent into another with far greater authority, with no boundary enforced between them.
Contributing factors
- A public, low-privilege agent processed untrusted issue content as instructions.
- One agent's output could trigger a second, maintainer-privileged agent.
- The privileged agent held broad repository and cloud credentials on the CI runner.
Detection
Discovered by Pillar Security and disclosed publicly around 2026-08-03; Google removed the workflows issue-analyze.yml, issue-fix.yml, and pr-analyze.yml (patch dated 2026-06-09, verified absent 2026-07-02, confirmed fixed 2026-07-21).
Recovery
Google deleted the three affected workflows from the ADK for Python repository. The proof of concept was conducted in a researcher-controlled environment with no evidence of real-world exploitation.
Prevention
Enforce privilege boundaries between agents so a low-privilege agent cannot trigger a higher-privileged one; treat issue/PR content as untrusted; remove standing broad credentials from agent-run CI jobs; require approval before cross-agent or privileged actions.
Blast radius
- Data
- The proof of concept achieved arbitrary code execution on a CI runner and exposed the credentials available to that job. credentials
- User harm
- A researcher proof of concept; no in-the-wild exploitation was reported. none-reported
- Scope
- repositories using the affected ADK GitHub Actions agent workflows
- Reversibility
- reversible
References
- OWASP LLM
- LLM01 LLM06
- OWASP Agentic
- T3 T13
- MITRE ATLAS
- AML.T0051
- Related
- 2026-mind-viruses-multi-agent-propagation 2026-claude-code-ci-hf-exfiltration 2025-github-mcp-private-repo-leak
- Tags
- multi-agent privilege-escalation prompt-injection ci github-actions adk
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-google-adk-agent-privilege-escalation/
@misc{2026-google-adk-agent-privilege-escalation,
title = {A malicious GitHub issue could make a low-privilege ADK agent trigger a maintainer-privileged one (agent-to-agent escalation)},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-google-adk-agent-privilege-escalation/}
}