Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The United States Is Betting the House on Winning the Artificial Intelligence Race With China

    August 5, 2026

    US stock market hits record high amid hopes for Strait of Hormuz reopening | Financial Markets News

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The United States Is Betting the House on Winning the Artificial Intelligence Race With China
    • US stock market hits record high amid hopes for Strait of Hormuz reopening | Financial Markets News
    • Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO
    • Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour
    • AIPAC Spending Dominates the Michigan Democratic Senate Primary
    • This Android launcher made my home screen fun again – and I’m using the free version
    • Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
    • This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 04, 2026AI Security / DevSecOps

    Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.

    The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied the privileged workflow’s owner, member, or collaborator gate. The trusted bot identity became the authorization bridge.

    The team demonstrated arbitrary code execution on the continuous integration (CI) runner and exfiltration of the bot personal access token (PAT). The privileged job also held a Google API key and a Google Cloud service-account credential. Its researcher-controlled proof-of-concept attacks do not identify in-the-wild exploitation or a compromised ADK release.

    The exposed component was the repository automation, not a flaw in the distributed ADK Python package. For similar repositories, Pillar recommends separate bot identities, narrower token and tool scopes, and an authorization signal that untrusted text cannot generate.

    The Hacker News contacted Google about the bot token’s scopes, service-account permissions, and exploitation evidence, and Pillar Security about the proof-of-concept environment and credential access. Both responses were pending at the time of writing.

    Cybersecurity

    The attack path began in the public issue-analyze.yml workflow, which ran automatically whenever an issue was opened. It authenticated with ADK_GCP_SA_KEY, supplied ADK_TRIAGE_AGENT and GOOGLE_API_KEY to Google’s Antigravity coding agent, and posted the generated analysis as a comment using the bot account.

    A separate issue-fix.yml workflow listened for /adk-issue-fix comments and restricted execution to an owner, member, or collaborator. The gate checked who posted the command, not whether an outsider had manipulated the trusted account behind it.

    The privileged job declared write access to issues, repository contents, and pull requests. Those settings applied to GitHub’s generated GITHUB_TOKEN, not the ADK_TRIAGE_AGENT PAT the job actually used.

    Pillar said the PAT’s exact scopes were not public. The job checked out the repository with the PAT, authenticated to Google Cloud, and ran the agent with the PAT and API key in its environment. The workflow was designed to edit code, create an adk-bot fork, push a branch, and open a pull request. A bot-generated pull request from June 4 shows that the automation was operating in the repository.

    The runner rejected shell metacharacters and allowed only commands whose first token was gh or git. But the script enabled CapabilitiesConfig(), which Google’s Antigravity SDK documentation says turns on all tools, including writes. The agent could therefore write a payload and make an allowed Git command execute it through a custom hook path.

    Git’s documentation confirms that hooks are executable programs and that core.hooksPath can redirect Git to another directory. The allowlist narrowed command syntax, but file writes and Git still left a route to code execution.

    Cybersecurity

    Public artifacts do not establish whether the PAT could push directly to the main branch. Pillar said Google told it the service account had Vertex AI access in a dedicated GitHub-management project; broader permissions were not disclosed. Pillar’s report describes runner execution and credential exposure, but the public record does not establish the downstream repository or cloud reach of those credentials.

    The report also described an earlier chain that could create a false review trail through privileged Gemini workflows, but a maintainer still had to merge the pull request.

    Google’s removal commit says the workflows processed untrusted issue and pull-request content with broad repository credentials. Google deleted issue-analyze.yml, issue-fix.yml, and pr-analyze.yml in a patch whose metadata carries a June 9, 2026 author date.

    Pillar said it verified the workflows were absent on July 2 and that Google confirmed the issue fixed on July 21. A check by The Hacker News on August 4, 2026, found none of the three filenames in the repository’s current main-branch workflow directory.

    ADK agent Deletes GitHub Google issue Malicious Privileged trigger Workflows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

    CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

    TP-Link patches Omada ZTP flaws allowing hackers to breach networks

    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    Oligo Raises $60 Million for Runtime Security

    Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The United States Is Betting the House on Winning the Artificial Intelligence Race With China

    August 5, 2026

    US stock market hits record high amid hopes for Strait of Hormuz reopening | Financial Markets News

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The United States Is Betting the House on Winning the Artificial Intelligence Race With China

    August 5, 2026

    US stock market hits record high amid hopes for Strait of Hormuz reopening | Financial Markets News

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.