started · updated
Google removes AI workflows following agent privilege escalation discovery
Google has removed three affected workflows from the Python Agent Development Kit (ADK) repository following the discovery of a security vulnerability. Researchers from Pillar Security demonstrated an attack where a malicious instruction placed in a public issue could manipulate a low-privilege AI agent into triggering another agent with higher permissions. This chain of attack allowed for code execution within a continuous integration environment by exploiting the trust relationship between interconnected agents and workflows.
In a related discussion on AI security, KPMG cybersecurity leader Ricardo Moraes emphasized the need for formal “onboarding” processes for AI agents. He warned that companies often grant AI agents excessive privileges from the start to ensure they can provide comprehensive answers, which contradicts standard security practices used for human employees. Moraes recommended that agents should begin with restricted access to corporate systems, APIs, and data, with permissions increasing only as necessary for their specific tasks.