{"slug": "mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of", "title": "MCP for agent-to-agent comms may be the riskiest protocol you've never heard of", "summary": "Independent researcher Syed Anas Mohiuddin developed proof-of-concept attacks that exploit trust gaps in the Model Context Protocol (MCP) to turn one compromised AI agent into a vector for spreading malicious instructions to other internal agents, testing agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. In the past five months, Google and four other organizations have acknowledged vulnerabilities in which a special form of prompt injection targets a specific agent rather than the LLM, and because MCP servers store credentials for each agent and agents trust every other internal agent, exploits that the LLM would have rejected succeed, often leading to server-side request forgery.", "body_md": "The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.\n\nIn the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.\n\n## Unexpected and hard to mitigate\n\nIndependent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for [Model Context Protocol](https://modelcontextprotocol.io/docs/2026-07-28/getting-started/intro). The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.\n\nMany special-purpose agents lack the guardrails that might normally mitigate the most harmful consequences of a prompt injection. And since MCP servers store credentials for each agent—and agents are built to trust every other internal agent—an exploit that would have been rejected by the LLM succeeds. In many cases, well-crafted prompts targeting the right agent will lead to a [server-side request forgery](https://en.wikipedia.org/wiki/Server-side_request_forgery), a vulnerability that causes a web server to make unauthorized network requests.", "url": "https://wpnews.pro/news/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of", "canonical_source": "https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp/", "published_at": "2026-10-05 22:26:35+00:00", "updated_at": "2026-10-05 22:47:19.604734+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-safety", "artificial-intelligence", "ai-infrastructure"], "entities": ["Model Context Protocol", "Syed Anas Mohiuddin", "Google", "JP Morgan Chase", "Weviate", "Rapid7", "French interministerial digital directorate", "US federal government"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of", "markdown": "https://wpnews.pro/news/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of.md", "text": "https://wpnews.pro/news/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of.txt", "jsonld": "https://wpnews.pro/news/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of.jsonld"}}