skip to content
The Weighted Average

Wire

Google scans agent containers for two critical risks

Google put Agent Platform Vulnerability Assessment into preview with two finding categories for Gemini Enterprise Agent Platform containers: high or critical software vulnerabilities and critical plaintext secrets. The July 31 Google Cloud release notes name credentials, access tokens, and API keys, while the Security Command Center documentation says new AI Protection activations get the scanner automatically and existing customers must enable it; findings require the Premium or Enterprise tier. For teams evaluating Google’s integrated agent stack, this makes container scanning a native control, not a substitute for CI secret detection—rotate exposed credentials and remove them before deployment rather than waiting for a runtime finding.