agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

A malicious GitHub issue could make a low-privilege ADK agent trigger a maintainer-privileged one (agent-to-agent escalation)

2026-google-adk-agent-privilege-escalation · 2026-08-03

Researchers showed that GitHub Actions workflows in Google's open-source Agent Development Kit (ADK) for Python could be chained: a public, low-privilege triage agent was prompt-injected via a crafted issue into triggering a maintainer-only agent holding broad repository and cloud credentials, achieving code execution on the CI runner and exposing its secrets. Google removed three workflows.

System

Framework
Google Agent Development Kit (ADK) for Python — GitHub Actions agent workflows
Tools
github-actions, ci
Vendor
Google
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → multi-agent-failure/cascade → unsafe-action/unauthorized-write
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

An unprivileged party opened a crafted GitHub issue that prompt-injected the repository's public, low-privilege triage agent. That agent's output became the injection vector for a second, maintainer-only agent with broad repository and cloud credentials, which then executed attacker-controlled commands on the CI runner.

Root cause

A low-privilege agent acting on untrusted issue content could influence a higher-privilege agent, crossing a privilege boundary. Trust flowed from an untrusted, public entry point through one agent into another with far greater authority, with no boundary enforced between them.

Contributing factors

  • A public, low-privilege agent processed untrusted issue content as instructions.
  • One agent's output could trigger a second, maintainer-privileged agent.
  • The privileged agent held broad repository and cloud credentials on the CI runner.

Detection

Discovered by Pillar Security and disclosed publicly around 2026-08-03; Google removed the workflows issue-analyze.yml, issue-fix.yml, and pr-analyze.yml (patch dated 2026-06-09, verified absent 2026-07-02, confirmed fixed 2026-07-21).

Recovery

Google deleted the three affected workflows from the ADK for Python repository. The proof of concept was conducted in a researcher-controlled environment with no evidence of real-world exploitation.

Prevention

Enforce privilege boundaries between agents so a low-privilege agent cannot trigger a higher-privileged one; treat issue/PR content as untrusted; remove standing broad credentials from agent-run CI jobs; require approval before cross-agent or privileged actions.

Blast radius

Data
The proof of concept achieved arbitrary code execution on a CI runner and exposed the credentials available to that job. credentials
User harm
A researcher proof of concept; no in-the-wild exploitation was reported. none-reported
Scope
repositories using the affected ADK GitHub Actions agent workflows
Reversibility
reversible

References

OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051
Tags
multi-agent privilege-escalation prompt-injection ci github-actions adk

Sources

Cite this incident

@misc{2026-google-adk-agent-privilege-escalation,
  title = {A malicious GitHub issue could make a low-privilege ADK agent trigger a maintainer-privileged one (agent-to-agent escalation)},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-google-adk-agent-privilege-escalation/}
}