Build zero-trust AI agents with Google's ADK

Google's ADK team open-sourced a deliberately exploitable refund agent to argue that perimeter security is blind once an LLM chooses its own execution path through production systems.

Retrieval answer

Google's ADK team open-sourced a deliberately exploitable refund agent to argue that perimeter security is blind once an LLM chooses its own execution path through production systems.

Field note

Google's Agent Development Kit team published a zero-trust guide on 17 August built around a deliberately realistic target: an autonomous customer support and returns agent, written with ADK and Gemini, open-sourced with a runnable demo in a zero-trust-agents repository. The point of shipping the vulnerable thing is that defence patterns are only checkable against real exploits.

The argument underneath is about where the security boundary sits. A framework makes multi-tool autonomous workflows trivial to assemble, but the moment those sessions reach live databases, internal APIs and dynamic runtimes, the agent stops generating text and starts mutating production state: issuing refunds, modifying records, executing code. Because the model determines its own execution path in unstructured natural language, traditional perimeter security is blind to how the agent behaves internally, so the controls have to sit on each action rather than at the edge.

That is precisely the conclusion this site reached in agent security moving outside the model and in AISI's incident being an authorization failure rather than a sandbox failure. The agent security hub keeps the cases together.

This is a vendor engineering post with an open repository, not an audited threat model or a measured comparison of defence patterns. The condition to watch is whether the repository accumulates reproduced exploits and their mitigations over time, because a zero-trust demo that stays at one scenario teaches a pattern rather than a boundary.

Recommendation

Google's ADK team open-sourced a deliberately exploitable refund agent to argue that perimeter security is blind once an LLM chooses its own execution path through production systems.

Discovery graph / next reads

Continue through New Runtime

Open the graph
  1. 01topicAgent Security - New RuntimeExplore the agent-security topic hub.
  2. 02topicAgents - New RuntimeExplore the agents topic hub.
  3. 03topicAi - New RuntimeExplore the ai topic hub.
  4. 04archiveField NotesOpen the latest editorial analysis.
  5. 05source ledgerSource LedgerInspect the public source evidence graph.

These links are also published in this page's JSON twin and as typed edges in DiscoveryGraph v1.

Who read this page?Machine requests, hidden until opened

Loading the privacy-safe route aggregate...

Open the JSON contract