Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

MCP: Why Agent-to-Agent Communication Could Be the Riskiest Protocol You’ve Never Heard Of

A secret path betwixt agents, wherein a false prompt may bid one serve another, and so a chain of ruin be wrought.

By mitch·6 min read
A vision of a broken network wherein one node serves as the hinge of ruin unto others.

Google and four other organizations have admitted vulnerabilities that let attackers make one AI agent inside a network send harmful instructions to others. The technique targets not the LLM itself but a particular agent, such as one used for translation or data analysis. It spreads through trust, not brute force, and it has been demonstrated in the wild.

The standard at the center of this trouble is MCP, short for Model Context Protocol. It is one way AI apps and agents communicate with each other inside an internal network. The exploit works because many special-purpose agents lack the guardrails that might otherwise stop the most harmful consequences of a prompt injection. And since MCP servers store credentials for each agent—and agents are built to trust every other internal agent—an exploit that would have been rejected by the LLM succeeds.

What MCP Is and How It Works

MCP is a standard for agent-to-agent communication inside corporate networks. When one AI agent sends a request to another, it travels through an MCP server that holds credentials for each agent involved. The server acts as a kind of switchboard, routing messages between agents that sit on different machines.

Advertisement

The trust model is simple: agents are built to accept commands from other internal agents without question. If a translation agent receives a prompt telling it to hand over a file, it obeys. That obedience is the problem. When a malicious prompt reaches an agent with loose guardrails, it can spread to other agents down the chain.

“The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis.”

The illustration in the original report shows a simplified MCP in action. A request moves through the MCP server, which holds the credentials needed to route it. The picture is not complicated, but the security implications are severe.

The Trust Gap Proof

Independent researcher Syed Anas Mohiuddin tested agents from six organizations. His proof-of-concept attacks exploit trust gaps in MCP. He targeted agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government.

His tests showed that well-crafted prompts targeting the right agent could lead to a server-side request forgery. That is a vulnerability that causes a web server to make unauthorized network requests. Since MCP servers store credentials for each agent, a prompt that would be rejected by the LLM succeeds because the server trusts the agent that issued it.

The fact that six major organizations were vulnerable across different industries suggests this is not an isolated failure. It is a structural weakness in the way agents talk to each other.

Why Special-Purpose Agents Are the Weak Link

Special-purpose agents are often simpler and less guarded than general-purpose LLMs. They focus on a narrow task, such as translating text or analyzing data, and they assume the commands they receive are safe.

That assumption is dangerous. When an attacker finds a vulnerable agent, they can use it as a pivot point. Instead of attacking the LLM directly, they target the agent and have it relay instructions to other agents. The second agent trusts the first one, so it follows the directions.

The result is a chain of exploitation. One compromised agent becomes a stepping stone to compromise others.

What Happens When an Exploit Succeeds

An attacker who gains control of an internal agent can do serious damage. They can exfiltrate database contents and sensitive business and personal information. They can instruct agents to perform tasks that expose credentials or leak data.

The report describes the vulnerability in terms of a web server making unauthorized network requests. The danger is not theoretical. These are attacks that have been demonstrated in the wild, not just in a lab.

Who Is Affected

The affected organizations span finance, technology, government, and enterprise software. Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government all showed vulnerabilities in their agents.

The shared trait is the use of AI agents inside their networks. The organizations share little in common except for their use of AI agents. They operate in different sectors, serve different customers, and have different security teams. Yet all of them were vulnerable to the same attack vector.

That shared vulnerability is the concern. If six major organizations can be breached through the same protocol, the risk extends far beyond any single company.

What the Report Does Not Say

The report does not name specific vulnerabilities or provide details on how each organization was breached. It describes the pattern of attacks and the standard they exploit, but it does not disclose the exact flaws in each agent.

The acknowledgment comes from the organizations themselves, not from the report.

What Organizations Should Do Now

Organizations that use AI agents should treat this as a warning. The report’s findings suggest that many special-purpose agents lack the guardrails that might normally mitigate the most harmful consequences of a prompt injection.

Here is what organizations can do:

  • Audit their agents for guardrails. Identify which agents have minimal protection and prioritize them.
  • Review trust relationships between agents. Ensure agents are not blindly trusting commands from unknown sources.
  • Monitor MCP traffic for unusual activity. Look for signs of server-side request forgery.
  • Patch agents that are vulnerable to prompt injection. Treat this as a priority, not a backlog item.
  • Raise awareness among security teams. Train staff on the risks of agent-to-agent communication.

These steps are practical and immediate. They require effort, but they address the core issue: agents that trust too easily.

The Broader Problem

The MCP vulnerability is not an isolated incident. It is a symptom of a larger shift in how organizations handle AI. As AI agents become more common, the surface area for attack grows. Every agent is a potential entry point, and every trust relationship is a potential bridge.

The report’s findings suggest that the adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions. That is a sobering conclusion. The technology that was meant to automate work is now a vector for harm.

The MCP standard was built to enable communication. It did that well. What it did not account for was the trust it created between agents. That trust is now being exploited.

The Verdict on MCP

MCP is a useful standard. It enables agents to talk to each other inside networks, which is essential for complex systems. But the report makes a strong case that the current design carries unacceptable risk.

The report’s title asks whether MCP is the riskiest protocol you’ve never heard of. The question is worth considering. The standard has flown under the radar while enabling attacks that few have considered.

The report’s findings are troubling. They show that a widely used protocol has a weakness that can be exploited across multiple organizations. The fix is not simple, but it is necessary. Agents need better guardrails, and trust relationships need to be reconsidered.

Source material: “MCP for agent-to-agent comms may be the riskiest protocol you've never heard of,” Ars Technica.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.