MCP's agent-to-agent design carries serious security risks
Original: MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Why This Matters
MCP is fast becoming the backbone of multi-agent AI systems across the industry.
Anthropic's Model Context Protocol (MCP), used for agent-to-agent communication by Google and others, contains structural security flaws that expose AI systems to exploitation, per Ars Technica reporting.
MCP (Model Context Protocol), developed by Anthropic and adopted by major AI players including Google, is emerging as a standard for enabling AI agents to communicate with each other and with external tools. But security researchers have identified structural vulnerabilities in how MCP handles agent-to-agent interactions — flaws that aren't bugs in any single implementation, but problems baked into the protocol's design itself. Because MCP allows agents to invoke tools and pass instructions between systems, a compromised or malicious agent in the chain can manipulate downstream agents, potentially executing unintended actions. This is a form of prompt injection at the protocol level. Google's agent implementations are among those affected, suggesting the risk is not isolated. The concern is that MCP is being widely adopted before its security model is fully understood or hardened, creating a situation where the attack surface grows in proportion to the protocol's popularity.