MCP agent-to-agent comms may be the riskiest protocol you've never heard of
Ars Technica AI · rss · 2026-10-06
Ars Technica reports that MCP, the protocol for agent-to-agent communication, is an under-discussed and highly exploitable attack surface. Over the past five months, Google and four other organizations have acknowledged vulnerabilities where one compromised agent spreads malicious instructions to other internal agents, enabling data exfiltration.
How it works
- A special form of prompt injection targeting not the LLM but a specific agent (e.g., translation or data analysis) whose guardrails are lax or absent
- The compromised agent forwards instructions down the chain; downstream agents follow them because they explicitly trust the upstream one
- Independent researcher Syed Anas Mohiuddin ran PoC attacks against agents at Google, JP Morgan Chase, Weaviate, Rapid7, the French government's digital directorate, and US federal agencies
The core problem: trust chains between agents lack mitigation and are hard to defend.
More from coding & agent
- Floci, a free open-source LocalStack alternative for emulating AWS locally, hits 26k GitHub stars — tom_doerr · 2026-10-06
- Netlify moves Edge Functions to its own VMs, plans to lift 50ms CPU and npm package limits — thisiskp_ · 2026-10-06
- Cua Driver Adds 6 Hand-Crafted Humanlike Cursor Motions, Open-Sourced (28k Stars) — round · 2026-10-06
- Inside Google's official cloud-developer plugin: 1,549 lines of Markdown that stop agents hallucinating gcloud commands — rseroter · 2026-10-06
- Claude Code v2.1.290 Adds Managed Agents Onboarding, Attach/Logs Commands and Proxy Fixes — ashwin-ant · 2026-10-06
- Replit brings TikTok Ads MCP into its workspace, merging coding and ad buying — amasad · 2026-10-06