MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

用于代理间通信的 MCP 可能是你从未听说过的最高风险协议

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. 数以百万计的组织对 AI 代理的采用,正在为攻击者创造新的机会,诱导这些代理执行恶意操作,例如窃取数据库内容以及敏感的商业和个人信息。在过去的五个月里,谷歌和其他四个组织——除了都使用 AI 代理外几乎没有共同点——已经承认存在相关漏洞,这些漏洞利用目标网络内的一个代理,将有害指令传播给其他内部代理。

The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions. 这种技术是一种特殊形式的提示词注入(prompt injection),其目标不是大语言模型(LLM)本身,而是特定的代理,例如负责翻译或数据分析的代理。此类代理内部的防护机制(如果存在的话)通常很松懈,会将指令发送给链条下游的其他代理。由于后续的代理明确信任第一个代理,因此它会执行这些指令。

Unexpected and hard to mitigate

意外且难以缓解

Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action. 独立研究员 Syed Anas Mohiuddin 测试了包括谷歌、摩根大通、Weviate、Rapid7、法国政府跨部门数字局以及美国联邦政府在内的多个组织的代理。他的概念验证攻击利用了 MCP(模型上下文协议,Model Context Protocol)中的信任缺口。该标准是 AI 应用和代理在内部网络中相互通信的一种方式。下图展示了简化的 MCP 工作流程。

Many special-purpose agents lack the guardrails that might normally mitigate the most harmful consequences of a prompt injection. And since MCP servers store credentials for each agent—and agents are built to trust every other internal agent—an exploit that would have been rejected by the LLM succeeds. In many cases, well-crafted prompts targeting the right agent will lead to a server-side request forgery, a vulnerability that causes a web server to make unauthorized network requests. 许多专用代理缺乏能够缓解提示词注入最严重后果的防护机制。由于 MCP 服务器存储了每个代理的凭据,且代理被设计为信任网络内的所有其他代理,因此原本会被 LLM 拒绝的攻击往往能够成功。在许多情况下,针对特定代理精心设计的提示词会导致服务器端请求伪造(SSRF),这是一种诱导 Web 服务器发起未经授权网络请求的漏洞。

“AI agents give attackers a fresh set of connections to walk across,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. “Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.” Rapid7 漏洞情报总监 Douglas McKee 对 Ars 表示:“AI 代理为攻击者提供了一套全新的连接路径。有人在内容中植入文本,代理读取后将其作为正常的委派任务传递给另一个代理,而第二个代理因为信任交付任务的对象,便会执行该任务。链条中的每一个环节都完全按照其设计意图运行,这正是此类问题难以察觉的原因。每个协议在构建时都假设自己是独立运行的,因此每个协议只检查自己的前门,却没有人看管中间的走廊。”

CVE-2026-97228, the vulnerability Mohiuddin found in Rapid7’s network, carried a severity rating of only 2.7 out of 10. Rapid7 fixed it last month. The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL returning an error or redirecting to a different URL. Google’s HTTP client also failed to validate target IP addresses. Mohiuddin 在 Rapid7 网络中发现的漏洞 CVE-2026-97228 的严重性评级仅为 2.7(满分 10 分)。Rapid7 已于上个月修复了该漏洞。影响谷歌的漏洞则更为严重,评级为 8。它源于一个用于数据库的 MCP 工具箱(googleapis/mcp-toolbox),该工具箱在初始化 HTTP 客户端时未使用 CheckRedirect 策略——这是一系列用于控制服务器如何处理 URL 返回错误或重定向到不同 URL 的设置。谷歌的 HTTP 客户端也未能验证目标 IP 地址。

“A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mohiuddin explained. Google’s fix involved applying an allow-list of IP ranges and block lists. “It rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done.” “一个精心构造的路径参数可以诱导工具箱重定向到内部端点,并代表攻击者发送请求,”Mohiuddin 解释道。谷歌的修复方案包括应用 IP 范围的白名单和黑名单。“它在启动时就拒绝了不安全的基准 URL,而不是等到第一次请求时才拒绝。这才是真正的 SSRF 防护。这也比大多数 MCP 服务器所做的防护工作要多得多。”

Mohiuddin is calling the class of attack “protocol pivoting” because the exploits work when an app or server uses MCP to assign a task to an agent and the agent then forwards malicious instructions to another agent using a different communication method such as Google’s Agent-to-Agent (A2A) protocol, used for inter-agent delegation, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization gets effectively lost in translation. He described protocol pivoting as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.” Mohiuddin 将此类攻击称为“协议枢轴(protocol pivoting)”,因为当应用或服务器使用 MCP 将任务分配给代理,而该代理随后使用另一种通信方式(如谷歌用于代理间委派的 A2A 协议,或新兴的代理网络协议)将恶意指令转发给另一个代理时,这种攻击便会生效。他表示,信任或授权往往在转换过程中丢失了。他将协议枢轴描述为“一种多步骤攻击,攻击者通过一种协议获得初始访问权限,利用协议之间的信任假设,并升级到仅通过不同协议才能访问的功能。”

Markus Vervier, a researcher at X41 D-Sec who has also devised AI attacks that exploit MCP, said the better term remains “prompt injection” and that Mohiuddin’s technique is a simple subclass of that. “For me this is indirect prompt injection,” he told Ars. “The fact that the malicious prompt can come from a different protocol (e.g., A2A) and manifests when used over another protocol is not strictly required for such attacks to work. It is, of course, unexpected and hard to mitigate in general.” X41 D-Sec 的研究员 Markus Vervier 也曾设计过利用 MCP 的 AI 攻击,他认为更好的术语仍然是“提示词注入”,而 Mohiuddin 的技术只是其中的一个简单子类。“对我来说,这是间接提示词注入,”他告诉 Ars。“恶意提示词可以来自不同的协议(例如 A2A)并在通过另一个协议使用时显现,这一事实并非此类攻击生效的严格必要条件。当然,这在总体上是出人意料且难以缓解的。”

The fact that the pivoting technique worked across five organizations with nothing in common other than the use of MCP is notable. MCP is new and is already everywhere before it has been sufficiently tested and hardened. In organizations’ rush to build sprawling agentic architectures, they have abandoned a core security principle known as zero trust. Under that model, networks are built with the assumption that one or more nodes may be infected. To mitigate the effects, engineers must design nodes to require authorization before conducting sensitive transactions with other ones. 这种枢轴攻击技术在五个除了使用 MCP 外毫无共同点的组织中均能奏效,这一点值得注意。MCP 是一个新事物,在尚未经过充分测试和加固之前就已经无处不在。在组织急于构建庞大的代理架构时,他们抛弃了一个核心安全原则——零信任。在该模型下,网络的构建假设是一个或多个节点可能已被感染。为了减轻影响,工程师必须设计节点,要求在与其他节点进行敏感交易之前必须获得授权。

“The lesson I’d want people to take away is that anything passed from an LLM to your tool should be treated like input from a stranger on the internet, because in a prompt injection scenario that’s exactly what it is,” McKee said. The bugs underneath are old friends like injection and SSRF, and the fixes haven’t changed in 20 years. Credit to the researcher for putting a name on it, because a name is what gets defenders and standards bodies to actually design for it. “我希望人们吸取的教训是,任何从 LLM 传递到你的工具的内容,都应该被视为来自互联网陌生人的输入,因为在提示词注入场景中,事实确实如此,”McKee 说道。其底层的漏洞依然是注入和 SSRF 等“老朋友”,而修复方法在过去 20 年里并没有改变。感谢这位研究员为它命名,因为一个名称才能促使防御者和标准制定机构真正地去针对它进行设计。