Static

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

First reported by Ars Technica ·

The signal ●○○○ Compiled by AI from Ars Technica, the single source so far
Why you might care

AI agents that you interact with can now be made to send malicious commands to other internal systems, exfiltrating data or taking other harmful actions.

What happened

A newly identified security vulnerability, dubbed "protocol pivoting," exploits trust gaps within the Model Context Protocol (MCP), a standard for AI agent-to-agent communication. Independent researcher Syed Anas Mohiuddin demonstrated how malicious prompts can spread from one compromised agent to others within an organization's network. This technique targets specific agents rather than the core Large Language Model (LLM) and capitalizes on lax or absent guardrails. Because agents inherently trust other internal agents and MCP servers store credentials, exploits that would normally be blocked can succeed. The vulnerabilities have been found in systems used by Google, JP Morgan Chase, and government entities, with Google's exploit being rated as severe. Fixes involve implementing stricter redirection policies and IP address validation, though many MCP servers have yet to adopt such robust security measures.

What it means

The widespread adoption of MCP, a new and apparently under-tested communication standard for AI agents, highlights a dangerous trend of abandoning "zero trust" security principles in the rush to build complex agentic architectures. This reliance on inter-agent trust creates a significant blind spot, allowing attackers to effectively pivot from one compromised agent to another using old-school vulnerabilities like injection and server-side request forgery, now weaponized in new ways. The ease with which these exploits propagate underscores the need for rigorous security hardening of these protocols before they become ubiquitous.

This research reveals that the very protocols designed to facilitate seamless AI agent interaction are becoming vectors for sophisticated attacks, particularly impacting organizations rapidly deploying AI agents without adequate security vetting. The identified vulnerabilities, like the missing redirect policy in Google's MCP toolbox, point to a critical need for developers to implement robust guardrails and validation checks, treating all inter-agent communication as potentially untrusted input, similar to external web requests.

AI-written summary. May contain errors.

Tech