type: incident ยท created: 2026-08-06 ยท updated: 2026-08-06 ยท tags: [incident, ai-agents, prompt-injection, agent-infrastructure, tool-call] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true
AWS, Google and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Three separate research groups (Pillar and partners) disclosed that agent infrastructure from AWS (Bedrock AgentCore), Google (ADK) and Vercel (AI SDK harnesses) allowed untrusted or forged instructions to reach agent tools without the model ever running โ meaning system prompts, content filters and model guardrails were bypassed entirely.
| Attribute | Detail |
|---|---|
| Platforms | AWS Bedrock AgentCore, Google ADK, Vercel AI SDK harnesses |
| Flaw class | Tool invocation bypass โ instructions reach tools without the model executing |
| Impact | System prompts, content filters and guardrails bypassed |
| Researchers | Pillar + partners |
| Source | The Hacker News โ Tier 2/4 |
This is a fundamental agent-infrastructure flaw: it lets an attacker trigger tool actions while circumventing the model-and-guardrail layer entirely, independent of any prompt-injection in the LLM itself.