Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cameroon’s President Biya reshuffles army amid unease at his long stay in Switzerland

    August 4, 2026

    Prisoner early release scheme gives Burnham his first taste of unpopularity | Andy Burnham

    August 4, 2026

    Fifa executive criticises Gianni Infantino’s ‘reproachable’ stake sale plan

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cameroon’s President Biya reshuffles army amid unease at his long stay in Switzerland
    • Prisoner early release scheme gives Burnham his first taste of unpopularity | Andy Burnham
    • Fifa executive criticises Gianni Infantino’s ‘reproachable’ stake sale plan
    • The Best Cordless Vacuums (2026): My Brand-New Top Pick
    • The Minnesota attackers may hold a better backup of your plant than you do
    • Sorry Everyone, but Bitcoin is Headed Down to $43,500: Michael Terpin
    • Scientists twist crystal layers and reshape matter from within
    • Global hunger levels fall but Africa still lags behind, UN report finds
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Pillar Security discovered an agent-to-agent attack method in Google’s Agent Development Kit for Python that could lead to secret exposure and pull request (PR) poisoning.

    The google/adk-python repository had two classes of automated AI agents, namely low-privileged ones open to user interaction, and high-privileged ones accessible only to maintainers.

    An attacker could manipulate the low-privileged, public-facing agent to pass a prompt to the high-privileged one, gaining access to restricted capabilities, including command execution, and potentially opening the door to supply chain compromise, Pillar’s Dan Lisichkin explains.

    Initially, the company discovered that an agent responsible for triaging pull requests was commenting on PRs as a Collaborator, meaning it has high privileges on the repository.

    Next, Lisichkin found a way to manipulate the agent into posting an @gemini-cli as a comment on a PR, which triggered gemini-invoke and provided access to a more privileged workflow.

    The initial prompt triggered a response from the gemini_invoke.yml workflow that leaked the tools the privileged agent had access to via the MCP server.

    Advertisement. Scroll to continue reading.

    This revealed that the bot had access to every bash command, meaning that the researcher could execute code remotely and potentially extract the agent’s GitHub token.

    According to Lisichkin, this allowed him to modify the comments, PRs, and issues of other maintainers, collaborators, and members; dismiss reviews or approve PR changes; and invoke gemini-invoke and gemini-review against any PR.

    This also enabled the researcher to poison the PR approval lifecycle, but any malicious PR would have to be approved and merged by a member, which required social engineering.

    The attack scenario would require a threat actor to build trust as a collaborator, then open a PR containing malicious code, which would be marked for review. The threat actor could then open a second PR containing prompts that would instruct the agent to mark the first PR as triaged, reviewed, and approved.

    “Editing the triager’s comment uses the impersonation primitive from issues: write; posting and approving as the bot uses the RCE-extracted GITHUB_TOKEN; the label and review-request changes fall under pull-requests: write. Strung together, they manufacture a complete, believable ‘a human asked for a review, Gemini ran it, Gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin notes.

    Google was notified of the finding in early June and addressed the issue through hardening, but did not consider it to meet the bar for a bug bounty reward, as it required social engineering to merge the malicious PR.

    Shortly after, Pillar discovered another vulnerability in the ADK repository, in the automation features of the Antigravity-SDK-based agent, which could lead to remote code execution without a maintainer’s interaction. Google fixed the weakness in late July.

    Related: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

    Related: Ruby on Rails Patches Critical Vulnerability

    Related: Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    Related: Critical Code Execution Vulnerability Patched in TeamCity

    AgenttoAgent attack Enabled exposed Gemini method pull request Secrets Tampering
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The Minnesota attackers may hold a better backup of your plant than you do

    When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

    OpenAI hits back at Apple over ‘oddly personal’ trade secrets fight

    Secure AI adoption starts with API best practices

    CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

    150,000 Impacted by Madera Community Hospital Data Breach

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cameroon’s President Biya reshuffles army amid unease at his long stay in Switzerland

    August 4, 2026

    Prisoner early release scheme gives Burnham his first taste of unpopularity | Andy Burnham

    August 4, 2026

    Fifa executive criticises Gianni Infantino’s ‘reproachable’ stake sale plan

    August 4, 2026

    The Best Cordless Vacuums (2026): My Brand-New Top Pick

    August 4, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cameroon’s President Biya reshuffles army amid unease at his long stay in Switzerland

    August 4, 2026

    Prisoner early release scheme gives Burnham his first taste of unpopularity | Andy Burnham

    August 4, 2026

    Fifa executive criticises Gianni Infantino’s ‘reproachable’ stake sale plan

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.