Whispers of Wealth: Red-Teaming Google’s Agent Payments Protocol
Published:
Conducted AI red-teaming research on Google’s Agent Payments Protocol (AP2) by building a functional agent-based prototype and performing adversarial prompt-injection testing to evaluate security risks in conversational payment systems.
Identified vulnerabilities including:
- Unauthorized tool invocation
- Data exfiltration
- Manipulation of payment authorization flows
Designed Branded Whisper and Vault Whisper attacks and proposed mitigation strategies for safer agentic commerce systems.
Research Areas:
Agentic AI, AI Security, Prompt Injection, Financial Agents, Red-Teaming, LLM Security
