Analysis · curated 15 Jul 2026
Mitigate indirect prompt injection risks from Google Cloud MCP | Google Cloud Data Agent Kit extension for Antigravity IDE | Google Cloud Documentation
First reported google.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
Coding agents wired to Google Cloud MCP inherit the user's privileges and can be steered by indirect prompt injection hidden in data sources, so defenders need these mitigation guardrails to prevent agent-driven data access or exfiltration.
Google Cloud documentation for the Data Agent Kit extension in the Antigravity IDE describes indirect prompt injection risks from Google Cloud MCP, where locally deployed coding agents running with a user's full privileges can misinterpret attacker-planted data (e.g., in email, calendar, Cloud Storage, or BigQuery) as instructions. The guidance recommends guardrails such as running agents in constrained environments to reduce risk to infrastructure and data.