A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a software supply chain. The flaw was found in google/adk-python, the repository behind Google’s Agent Development Kit for Python, an SDK widely used by developers to build their own AI agents. The adk-python repository ran two tiers of automated AI agents. A low-privileged agent handled public-facing interactions, triggered whenever a user opened a pull request or issue, while a high-privileged agent was reserved for trusted maintainers with real authority over the codebase. Pillar’s researchers discovered that the low-privileged,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!