MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

by | Oct 6, 2026 | Technology

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Security researchers have identified a class of attacks targeting the Model Context Protocol (MCP), a communication standard used by AI agents within internal networks. Independent researcher Syed Anas Mohiuddin demonstrated vulnerabilities affecting Google and four other major organizations that share no commonalities beyond their use of AI agents.

The attack method exploits trust gaps between connected agents. When one agent receives malicious instructions embedded in content, it may forward them to other agents as routine delegated tasks. Since agents are typically configured to trust instructions from other internal agents, these malicious directives execute successfully. The technique represents a specialized form of prompt injection that targets specific agents rather than the underlying language models. Many purpose-built agents lack robust security guardrails, making them susceptible to such attacks.

Mohiuddin’s research identified several notable vulnerabilities. A flaw in Rapid7’s network received a severity rating of 2.7 out of 10 and has been addressed. Google’s vulnerability proved more severe with a rating of 8, stemming from improper handling of HTTP client redirects and insufficient IP address validation in a database toolbox. The exploit could allow attackers to redirect requests to internal endpoints and execute unauthorized actions on their behalf.

Mohiuddin describes the attack pattern as “protocol pivoting,” referring to scenarios where malicious instructions transition between different communication protocols, such as from MCP to Google’s Agent-to-Agent protocol. Other security researchers debate terminology, with some preferring the classification of “indirect prompt injection.” Regardless of nomenclature, the underlying vulnerabilities relate to established security issues including injection attacks and server-side request forgery.

Exerts emphasize that the rapid deployment of MCP across organizations before thorough security hardening has introduced risk. The attacks underscore the importance of implementing zero-trust security principles in agent architectures, treating all data from language models as potentially untrusted input and requiring authorization for sensitive inter-agent transactions.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI