{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Secure Talk Podcast","title":"AI Agent Hacks Another AI Agent Inside Google — An Agentic Supply Chain Bomb","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/b055eda6\"></iframe>","width":"100%","height":180,"duration":3024,"description":"An agent anyone could talk to just pulled the levers on one almost nobody could reach — and it happened inside the crown jewels: a live code repository.\nGoogle gave its AI agent human-level trust — and paid for it.\nWhen Dan Lisichkin, a researcher at Pillar Security, started mapping every Google repository running an embedded coding agent, he wasn't hunting for prompt injection — he was hunting classic CI/CD bugs. The AI angle showed up almost by accident, flagged by his own automation. What he found inside Google's Agent Development Kit repository was a low-privilege issue-triaging bot commenting on GitHub *as a trusted collaborator* — a status that should be reserved for humans the maintainers know. As Dan puts it, describing the moment his manager pushed back on downplaying the find: *\"this is an agent triggering another agent... this is like no one talked about this before.\"*\nThe prompt injection wasn't the hard part — weaponizing it was.\nDan walks through Pillar's CFS framework (Context, Format awareness, instruction Salience) and how he literally used Google's own CONTRIBUTING.md file as the blueprint for the injection that would slip past the triage agent undetected. From there, one gated comment — normally reserved for trusted maintainers — was enough to trigger a second, far more privileged agent.\nThis isn't a bug you patch once — it's a new attack surface.\nDan's read is blunt: multi-agent systems create \"weird machine\" behavior — undefined states nobody designed for, not flaws in a specific line of code. He and Justin dig into why bolting more rules onto a non-deterministic system is Sisyphean, why bot identities need database-row-level granularity instead of human-style trust, and why Dan — a former malware researcher — thinks mandatory human-in-the-loop is often the wrong answer at scale.\nChapters: \n00:00: Cold Open: The Agent That Wasn't Supposed to Talk**\n- Google's public triage bot and the collaborator-status anomaly\n- Why \"an agent triggering...","thumbnail_url":"https://img.transistorcdn.com/FI5U-V5f7xdITFyeJIbD7DHq2VtWIj7V7SxzbEqbbTM/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NzRj/MTkwYWEwN2IzMjIw/ZjRhZTE0MGJiYjhi/N2YxMS5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}