Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    GrapheneOS confirms the first Motorola to support the privacy-focused Android fork

    September 24, 2026

    We can’t create your rule right now says Outlook

    September 24, 2026

    US troops nearly boarded a Chinese ship after a chatbot invented a fake nuclear weapons cargo story

    September 24, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
    Cybersecurity

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    The Tech GuyBy The Tech GuyAugust 4, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Pillar Security discovered an agent-to-agent attack method in Google’s Agent Development Kit for Python that could lead to secret exposure and pull request (PR) poisoning.

    Advertisement

    The google/adk-python repository had two classes of automated AI agents, namely low-privileged ones open to user interaction, and high-privileged ones accessible only to maintainers.

    An attacker could manipulate the low-privileged, public-facing agent to pass a prompt to the high-privileged one, gaining access to restricted capabilities, including command execution, and potentially opening the door to supply chain compromise, Pillar’s Dan Lisichkin explains.

    Initially, the company discovered that an agent responsible for triaging pull requests was commenting on PRs as a Collaborator, meaning it has high privileges on the repository.

    Next, Lisichkin found a way to manipulate the agent into posting an @gemini-cli as a comment on a PR, which triggered gemini-invoke and provided access to a more privileged workflow.

    The initial prompt triggered a response from the gemini_invoke.yml workflow that leaked the tools the privileged agent had access to via the MCP server.

    Advertisement. Scroll to continue reading.

    This revealed that the bot had access to every bash command, meaning that the researcher could execute code remotely and potentially extract the agent’s GitHub token.

    According to Lisichkin, this allowed him to modify the comments, PRs, and issues of other maintainers, collaborators, and members; dismiss reviews or approve PR changes; and invoke gemini-invoke and gemini-review against any PR.

    This also enabled the researcher to poison the PR approval lifecycle, but any malicious PR would have to be approved and merged by a member, which required social engineering.

    The attack scenario would require a threat actor to build trust as a collaborator, then open a PR containing malicious code, which would be marked for review. The threat actor could then open a second PR containing prompts that would instruct the agent to mark the first PR as triaged, reviewed, and approved.

    “Editing the triager’s comment uses the impersonation primitive from issues: write; posting and approving as the bot uses the RCE-extracted GITHUB_TOKEN; the label and review-request changes fall under pull-requests: write. Strung together, they manufacture a complete, believable ‘a human asked for a review, Gemini ran it, Gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin notes.

    Google was notified of the finding in early June and addressed the issue through hardening, but did not consider it to meet the bar for a bug bounty reward, as it required social engineering to merge the malicious PR.

    Shortly after, Pillar discovered another vulnerability in the ADK repository, in the automation features of the Antigravity-SDK-based agent, which could lead to remote code execution without a maintainer’s interaction. Google fixed the weakness in late July.

    Related: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

    Related: Ruby on Rails Patches Critical Vulnerability

    Related: Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    Related: Critical Code Execution Vulnerability Patched in TeamCity

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

    September 24, 2026

    Astrana Health Data Breach Impacts Private, Confidential Information

    September 24, 2026

    Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios

    September 24, 2026

    IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin

    September 23, 2026

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    September 23, 2026

    Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

    September 23, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    GrapheneOS confirms the first Motorola to support the privacy-focused Android fork

    September 24, 2026

    We can’t create your rule right now says Outlook

    September 24, 2026

    US troops nearly boarded a Chinese ship after a chatbot invented a fake nuclear weapons cargo story

    September 24, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.