MCP flaws could let malicious instructions spread between trusted AI agents
Security researcher Syed Anas Mohiuddin found that weaknesses in the Model Context Protocol (MCP), used by AI agents to communicate, can let malicious instructions pass from one trusted agent to another. The attacks could lead agents to make unauthorised network requests and expose sensitive information, showing how gaps between connected systems can create risks even when each component follows its intended role.
Mohiuddin tested systems associated with Google, JPMorgan Chase, Weaviate, Rapid7, the French government and the US federal government. Rapid7 fixed a flaw rated 2.7 out of 10 last month; a Google MCP database toolbox flaw was rated 8 and was fixed with checks that block unsafe IP ranges and URLs. He calls the broader attack method “protocol pivoting”: harmful instructions move between agents and communication protocols, such as MCP and Google’s Agent-to-Agent protocol, while trust or authorisation is lost in the hand-off.
- MCP trust gaps can pass malicious prompts between AI agents.
- Google’s toolbox flaw was rated 8 out of 10.
- Protocol changes can cause trust and authorisation checks to fail.
New here? Start with this
Artificial intelligence systems increasingly work together by exchanging information through standard methods. The Model Context Protocol is one of the main approaches used for this communication. When systems can share instructions and data with each other, they become more capable, but this connectivity also creates security risks.
When AI systems are connected together, security weaknesses can develop. Harmful instructions from one system could potentially pass through to another system and be accepted as legitimate, even though each system may have built-in safety measures. The issue is that protections in place at one stage can be lost when information moves to the next system.
These vulnerabilities matter because they could allow connected AI systems to take actions they shouldn't or expose sensitive information. Major organisations including Google, JPMorgan Chase and government agencies use these communication methods, so it is important to fix the security gaps and prevent breaches across interconnected systems.
Read the full article at the source →
Originally published by Ars Technica as “MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of”.