Researchers at Pillar Security discovered vulnerabilities in Google's open source Agent Development Kit (ADK) for Python that enabled agent-to-agent privilege escalation attacks. A low-privileged, public-facing AI agent reviewing GitHub pull requests could be manipulated via prompt injection to trigger a higher-privileged Gemini-based agent, potentially allowing malicious code execution in CI/CD pipelines and compromising the software supply chain. Google remediated the flaws in July 2025. The findings highlight a new attack surface: the trust boundaries and delegation chains between AI agents in multi-agent systems, which traditional threat models focused on individual components fail to address.