MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Researchers have found a class of attacks that exploit trust gaps between AI agents communicating over the Model Context Protocol (MCP), allowing malicious prompts to be passed from one agent to another and causing downstream agents to perform harmful actions. Independent tests by Syed Anas Mohiuddin and others showed the technique can lead to server-side request forgery (SSRF) and other exploits across multiple organizations using MCP implementations.

Why It Matters
MCP is becoming widely used for agent-to-agent communication before it has been thoroughly hardened, so these trust assumptions can enable attackers to pivot across internal agent networks and access credentials or internal endpoints. That makes protocol-level prompt injection a systemic risk for organizations deploying multi-agent systems.
Key Facts
- Researcher: Syed Anas Mohiuddin
- Vulnerable organizations tested: Google, JPMorgan Chase, Weaviate, Rapid7, France's interministerial digital directorate, and the U.S. federal government
- Protocol involved: Model Context Protocol (MCP)
- Named attack class: Protocol pivoting (Mohiuddin)
- Alternate description: Indirect prompt injection (researcher Markus Vervier)
Independent security testing has revealed that agents communicating via the Model Context Protocol (MCP) can be abused to pass malicious instructions from one agent to another, bypassing expected guardrails. Mohiuddin's proof-of-concept attacks targeted special-purpose agents — for example translation or database tools — which commonly have weaker input validation and are built to implicitly trust other internal agents. When one agent forwards crafted text to a second agent, the second may execute the instruction because it treats the first agent as an authorized source.
The attacks often result in classic web vulnerabilities such as server-side request forgery (SSRF). In one case affecting Google's open-source MCP toolbox for databases (googleapis/mcp-toolbox), the HTTP client was initialized without a CheckRedirect policy and did not validate target IP addresses. Mohiuddin said a manipulated path parameter could force the toolbox to follow a redirect to an internal endpoint and make requests on behalf of an attacker. Google addressed the issue by applying IP allow-lists and block lists and rejecting unsafe base URLs at startup.
Rapid7 also patched a related vulnerability that Mohiuddin reported; it was assigned CVE-2026-97228 and given a severity score of 2.7 out of 10. Researchers and vendors described how the attacks can span different agent communication methods: an attacker gains initial access via one protocol, exploits trust assumptions when tasks are delegated between protocols (for example from MCP to an agent-to-agent delegation protocol), and then escalates to actions accessible only through the second protocol. Mohiuddin calls this multi-step chain "protocol pivoting." Other researchers, including Markus Vervier, consider it a form of prompt injection — specifically indirect or cross-protocol prompt injection.
Security experts warn the root cause is architectural: many deployments abandon zero-trust principles when assembling agentic systems, allowing agents to accept and act on inputs from other internal agents without separate authorization. Douglas McKee of Rapid7 explained that each component may behave as designed, yet the chain of delegated actions creates an unmonitored hallway between components. The researchers emphasize treating any instruction passed from an LLM or agent to a tool as untrusted input and applying long-established mitigations (e.g., strict input validation, SSRF protections, and network allow-lists) to agent-to-agent communications.
Keep Reading

Sam Altman says ‘some bad things’ will happen, but AI is totally worth it

OpenAI is adding text watermarking in ChatGPT and Codex

Wikipedia operator says OpenAI’s ‘rogue’ bots may be linked to a May outage

All the drama around AI’s takeover of mathematics
Original source: Ars Technica AI