Urgent.News

What's breaking now, across thousands of outlets.

AI

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Trust gaps in the new protocol spread malicious prompts from one agent to another.

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

The Model Context Protocol (MCP) stands as a potentially hazardous communication method among AI agents within organizations. As AI agents proliferate across numerous entities, they become susceptible to malicious manipulation, potentially exposing sensitive data and personal information. Over the past five months, Google and four other companies—each employing AI agents—have disclosed vulnerabilities that enable an attacker to manipulate one agent to disseminate harmful instructions to other internal agents.

This technique constitutes a variant of prompt injection that specifically targets AI agents rather than the underlying language model. While guardrails may be present, they are frequently insufficient, allowing instructions to be relayed to subsequent agents in the chain. These agents, in turn, blindly obey the initial agent's directives, thereby amplifying the risk.

In his testing, independent researcher Syed Anas Mohiuddin discovered that several well-known organizations, such as Google, JP Morgan Chase, Weviate, Rapid7, and even government entities like France's interministerial digital directorate and the US federal government, are vulnerable to such attacks. The root cause lies in the Model Context Protocol (MCP), a communication standard enabling AI apps and agents to interact within an internal network.

Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at arstechnica.com →

More in AI

More from Monday 5 October →