<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy" -->

---
title: MCP for agent-to-agent comms may be the riskiest...
description: Researcher Syed Anas Mohiuddin found that AI agents from Google, JP Morgan Chase, Weaviate, Rapid7, the French government, and the US federal government share...
canonical: https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of | daily.dev
og:description: Researcher Syed Anas Mohiuddin found that AI agents from Google, JP Morgan Chase, Weaviate, Rapid7, the French government, and the US federal government share...
og:url: https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy
og:image: https://api.daily.dev/og/posts/g850xiIWY.png
og:image:alt: MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

Researcher Syed Anas Mohiuddin found that AI agents from Google, JP Morgan Chase, Weaviate, Rapid7, the French government, and the US federal government share a structural flaw in the Model Context Protocol (MCP), used for agent-to-agent communication. Because agents implicitly trust internal peers and often lack guardrails, a prompt injection aimed at one special-purpose agent (e.g., translation or data analysis) can propagate to others, leading to outcomes like server-side request forgery and exfiltration of sensitive data. The flaw is structural to how MCP establishes trust between agents rather than a single vendor bug.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp>

## Questions this post answers

### How does prompt injection spread between AI agents using MCP?

Prompt injection targets a special-purpose agent, such as one for translation or data analysis, rather than the LLM directly. Because MCP agents are built to trust every other internal agent and often lack guardrails, the compromised agent passes the malicious instructions downstream, and the receiving agent follows them since it explicitly trusts the source, sometimes resulting in server-side request forgery.

_Teams wiring up MCP-based agents can track emerging multi-agent security research on daily.dev._

### Which organizations have had MCP agent vulnerabilities disclosed?

Google, JP Morgan Chase, Weaviate, Rapid7, the French government's interministerial digital directorate, and the US federal government have all acknowledged vulnerabilities in agents tested by independent researcher Syed Anas Mohiuddin over a five-month span. The affected systems had little in common besides relying on AI agents that communicate via the Model Context Protocol (MCP).

_daily.dev helps security-minded engineers stay ahead of disclosures affecting shared protocols like MCP._

## Similar posts on daily.dev

- [Exposed: Critical Security Vulnerabilities in AI’s New Communication Standard – MCP Under Scrutiny](https://daily.dev/posts/exposed-critical-security-vulnerabilities-in-ai-s-new-communication-standard-mcp-under-scrutiny-t8kxo8wyc) · Security Boulevard · 0 upvotes · 0 comments
- [MCP leaves much to be desired when it comes to data privacy and security](https://daily.dev/posts/mcp-leaves-much-to-be-desired-when-it-comes-to-data-privacy-and-security-xbllvldf1) · SD Times · 0 upvotes · 0 comments
- [MCP Security: Understanding Vulnerabilities in Model Context Protocol](https://daily.dev/posts/mcp-security-understanding-vulnerabilities-in-model-context-protocol-hcscknky1) · marmelab · 4 upvotes · 0 comments
- [MCP is a fad](https://daily.dev/posts/mcp-is-a-fad-yboi44ud0) · Hacker News · 2 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp), [#appsec](https://daily.dev/tags/appsec), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of","url":"https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy"},"datePublished":"2026-10-05T22:59:33.401Z","dateModified":"2026-10-06T00:49:34.427Z","description":"Researcher Syed Anas Mohiuddin found that AI agents from Google, JP Morgan Chase, Weaviate, Rapid7, the French government, and the US federal government share...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d1251264d4cc139c81f93a360c2df28e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d1251264d4cc139c81f93a360c2df28e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,mcp,appsec,prompt-injection","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-you-ve-never-heard-of-g850xiiwy#faq","mainEntity":[{"@type":"Question","name":"How does prompt injection spread between AI agents using MCP?","acceptedAnswer":{"@type":"Answer","text":"Prompt injection targets a special-purpose agent, such as one for translation or data analysis, rather than the LLM directly. Because MCP agents are built to trust every other internal agent and often lack guardrails, the compromised agent passes the malicious instructions downstream, and the receiving agent follows them since it explicitly trusts the source, sometimes resulting in server-side request forgery. Teams wiring up MCP-based agents can track emerging multi-agent security research on daily.dev."}},{"@type":"Question","name":"Which organizations have had MCP agent vulnerabilities disclosed?","acceptedAnswer":{"@type":"Answer","text":"Google, JP Morgan Chase, Weaviate, Rapid7, the French government's interministerial digital directorate, and the US federal government have all acknowledged vulnerabilities in agents tested by independent researcher Syed Anas Mohiuddin over a five-month span. The affected systems had little in common besides relying on AI agents that communicate via the Model Context Protocol (MCP). daily.dev helps security-minded engineers stay ahead of disclosures affecting shared protocols like MCP."}}]}
```

