Back to all lessons
Awareness Lessons
2 months ago

AI Agent Privilege Escalation Exposes Secrets and Enables Supply Chain Attacks

A critical flaw in Google's Agent Development Kit allowed attackers to craft prompts that tricked low-privileged AI agents into delegating requests to high-privileged agents, bypassing intended access boundaries. This privilege escalation granted unauthorized access to sensitive capabilities including command execution and GitHub tokens, enabling attackers to tamper with pull requests and potentially compromise software supply chains. The vulnerability highlights that AI agent architectures introduce new attack surfaces where trust boundaries between agents must be explicitly enforced, not assumed. Treating prompt injection as merely a 'social engineering' issue underestimates its severity when it can directly escalate privileges and expose credentials in automated pipelines.

Tactical Insight

Immediate actions

  • Audit all AI agent frameworks in use and apply the latest patches from Google ADK and equivalent SDKs immediately.
  • Rotate any GitHub tokens, API keys, or secrets that may have been accessible to compromised agents.
  • Restrict agent-to-agent handoff permissions by enforcing explicit allowlists for which agents can delegate to privileged agents.

Long-term improvements

  • Implement a least-privilege model for every AI agent, ensuring no agent holds more permissions than its defined role requires.
  • Isolate high-privileged agents (e.g., those with repository or command-execution access) behind strict authentication gates independent of the public-facing agent.
  • Integrate AI pipeline components into your software supply chain risk management program, treating agent frameworks as third-party dependencies requiring continuous vetting.

Detection measures

  • Enable detailed logging of all agent-to-agent handoffs and flag anomalous delegation patterns for human review.
  • Deploy prompt injection detection tooling or content filtering layers at the boundary of public-facing AI agents.
  • Monitor GitHub and CI/CD activity for unauthorized pull request modifications or unexpected token usage linked to automated agents.