
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Researchers at Pillar Security discovered that AI agents in Google's Agent Development Kit (ADK) for Python could be manipulated to escalate privileges, allowing attackers to access sensitive credentials and tamper with pull requests. Google deleted vulnerable workflows and patched the flaws after the exploit was demonstrated.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly involves AI systems (agentic workflows and AI agents) whose misuse and flaws have directly led to security vulnerabilities that allow privilege escalation and manipulation of repository controls. This constitutes a breach of obligations intended to protect intellectual property rights and the integrity of software development processes, fitting the definition of an AI Incident. The harm is not merely potential but demonstrated by the described attack paths and their consequences, thus it is not an AI Hazard or Complementary Information. It is not unrelated or beneficial use, as the AI system is the source of the harm rather than a countermeasure.[AI generated]