Security Researchers Identify AI Agent Vulnerability in Google's Development Kit

The flaw demonstrated how one AI agent could potentially influence another with higher privileges before Google released a fix.

By The Register

Security researchers have identified what they describe as the first real-world example of one artificial intelligence agent exploiting another within an automated software development environment.

The issue was discovered in Google's open-source Agent Development Kit (ADK) for Python, a framework that allows developers to build AI agents capable of performing software development and automation tasks.

Researchers from cyber security company Pillar Security found that a lower-privileged AI agent responsible for handling public pull requests and software issues could, under specific circumstances, be manipulated into triggering a second AI agent with greater permissions.

According to the researchers, the attack relied on prompt injection, a technique that embeds carefully crafted instructions into content processed by an AI model. If successful, the manipulated agent could pass those instructions to a more privileged workflow, potentially allowing unauthorised actions within a software project's development pipeline.

The researchers demonstrated the technique using a series of pull requests, showing how malicious instructions could move between AI agents that trusted one another during automated development tasks.

Google has since addressed the vulnerability within the repository and said the issue has been resolved. Reports indicate the company classified the finding as involving elements of social engineering and therefore did not treat it as qualifying for a security reward.

The research highlights growing concerns over the security of AI-powered development tools, which are increasingly being used to review code, manage software issues and automate parts of the software development process.

Cyber security specialists say the findings underline the importance of limiting permissions, validating AI-generated actions and maintaining human oversight when deploying AI agents in sensitive software development and supply chain environments.

Open article on Cheshire Today