AI agent protocol exposes organisations to cross-agent attacks, researchers warn

Google and others acknowledge vulnerabilities in Model Context Protocol, allowing malicious prompts to spread between trusted internal agents

By LineZotpaper
Published
Read Time2 min
A fundamental flaw in the Model Context Protocol (MCP), a standard used for communication between AI agents inside corporate networks, has left organisations including Google, JP Morgan Chase, and multiple government agencies vulnerable to attacks that can spread harmful instructions from one agent to another, independent security researchers have found.

The adoption of AI agents across millions of organisations is creating new opportunities for attackers to make these systems take malicious actions, such as exfiltrating database contents and sensitive business or personal information.

Over the past five months, Google and four other organisations with little in common except their use of AI agents have acknowledged vulnerabilities that allow attackers to exploit trust relationships between agents. The technique is a specific form of prompt injection that targets a particular agent — such as one handling translation or data analysis — rather than the underlying large language model. Guardrails inside such agents, where they exist at all, are often lax and will forward harmful instructions to other agents further down the chain. Because the downstream agent explicitly trusts the first one, it follows the directions.

Independent researcher Syed Anas Mohiuddin tested agents from organisations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, the Model Context Protocol, a standard that governs how AI applications and agents communicate inside an internal network.

Experts describe the vulnerability as unexpected and hard to mitigate, because it targets structural assumptions in how agents trust one another rather than a single software bug.

§

Analysis

Why This Matters

  • Organisations deploying AI agents for internal operations are exposed to a new class of attack that traditional security tools may not detect.
  • The vulnerability targets a core architectural assumption — agent-to-agent trust — and is therefore difficult to fix with patches alone.
  • Affected entities include major financial institutions, technology companies, and government agencies, raising the stakes for data protection and national security.

Background

MCP is a protocol designed to standardise communication between AI agents inside private networks. As organisations increasingly adopt multi-agent systems for tasks ranging from data analysis to customer service, the trust relationships between agents become critical. The attacks discovered by Mohiuddin exploit the fact that agents implicitly trust instructions from other agents within the same network, bypassing any guardrails that might exist at the point of entry. This is not a vulnerability in any single product but a structural weakness in how the protocol handles inter-agent trust.

Key Perspectives

Affected organisations: Google, JP Morgan Chase, and the others have acknowledged the vulnerabilities and are presumably working on mitigations, though the structural nature of the flaw makes a full fix difficult. Security researchers: They argue that MCP needs fundamental redesign to include trust boundaries and verification mechanisms between agents, rather than relying on implicit trust. Enterprise adopters: Organisations using AI agents face an urgent need to audit their deployments and implement additional guardrails, even as vendors work on protocol-level fixes.

What to Watch

  • Whether the MCP standard body issues an update that introduces agent-to-agent authentication or trust scoping.
  • Public disclosure of exploitation attempts against organisations using multi-agent AI systems.
  • Whether regulatory bodies, such as the US federal government, impose requirements on AI agent security postures.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.