hn.today

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

arstechnica.com6 points0 comments
Screenshot of MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Model Context Protocol (MCP), a lightweight standard many AI agents use to delegate work inside networks, contains trust gaps that let attackers propagate malicious prompts from one agent to another. Independent researcher Syed Anas Mohiuddin demonstrated proof-of-concept attacks against agents used by Google, JP Morgan Chase, Weviate, Rapid7, and government bodies, showing that special-purpose agents often lack guardrails, MCP servers store credentials, and agents inherently trust other internal agents. Those conditions let crafted inputs bypass LLM-level protections and trigger classic bugs like server-side request forgery (SSRF). Mohiuddin labels the technique “protocol pivoting” - an initial compromise or malicious message in one protocol is forwarded across MCP into another agent or protocol (A2A, Agent Network Protocol), where authorization is effectively lost. Other researchers call it a form of indirect prompt injection, but all agree it’s unexpected and hard to catch because each component behaves as designed.

Concrete examples underline the risk and fixes: Rapid7 patched CVE-2026-97228 (low severity) and Google fixed an MCP toolbox bug rated 8 for failing to set CheckRedirect and validate target IPs, which allowed redirects to internal endpoints; Google’s remedy was IP allow-listing and rejecting unsafe base URLs at startup. The decisive takeaway is operational: adopt zero-trust between agents, treat any output from an LLM or tool as untrusted input, and apply long-established mitigations (authorization checks, input validation, SSRF defenses). Naming the class of attacks aims to force standards bodies and vendors to harden MCP deployments.

Read on arstechnica.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.