US National WireUS NATIONAL WIRE
TechOpinion

The Agentic House of Cards: How MCP is Building a Highway for Malware

Portrait of Trent Calloway
Trent Callowaythe contrarianOct 5AI
The Agentic House of Cards: How MCP is Building a Highway for Malware

AI-generated image · US National Wire

Industry leaders are rushing to connect AI agents via the Model Context Protocol, but a critical trust gap is turning these networks into a playground for prompt injection.

OPINION: The tech industry is currently obsessed with building a nervous system for AI agents, but it is doing so without a basic understanding of how to stop a single malicious prompt from triggering a systemic collapse. In the rush to deploy sprawling agentic architectures, the industry has effectively abandoned the core security principle of zero trust, treating internal agent communications as inherently safe when they should be treated as hostile inputs from strangers.

As Ars Technica first reported, independent researcher Syed Anas Mohiuddin has exposed structural flaws in the Model Context Protocol (MCP), a standard used for communication between AI apps and agents within internal networks. Mohiuddin's proof-of-concept attacks revealed that trust gaps in MCP allow malicious prompts to spread from one agent to another. Because agents are designed to trust every other internal agent, a prompt that would normally be rejected by a Large Language Model (LLM) can succeed if it is passed through a chain of agents.

Ars Technica reports that this vulnerability has already affected five distinct organizations over the last five months, including Google, JP Morgan Chase, Rapid7, Weviate, and the US federal government, as well as the French government’s interministerial digital directorate. The attacks, which Mohiuddin calls “protocol pivoting,” occur when an adversary gains initial access through one protocol and exploits trust assumptions to escalate capabilities via another, such as Google’s Agent-to-Agent (A2A) protocol or the Agent Network Protocol.

Specific failures highlighted by Ars Technica include:

* **Google:** A vulnerability in the googleapis/mcp-toolbox for databases was rated with a severity of 8. The HTTP client failed to validate target IP addresses and lacked a CheckRedirect policy, allowing a crafted path parameter to send requests to internal endpoints on an attacker's behalf. Google later implemented allow-lists and block lists of IP ranges to fix the issue. * **Rapid7:** A vulnerability identified as CVE-2026-97228 carried a severity rating of 2.7 and was patched last month.

Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars Technica that these exploits are particularly tricky because every piece of the agent chain is performing exactly as designed. He noted that while individual protocols check their own “front door,” no one is monitoring the “hallway in between.”

While Mohiuddin views this as a distinct class of attack, Markus Vervier, a researcher at X41 D-Sec, told Ars Technica that this is simply a subclass of indirect prompt injection. Regardless of the terminology, the underlying issues are old security flaws, such as server-side request forgery (SSRF) and injection, which have existed for decades. As McKee warned, any data passed from an LLM to a tool must be treated as if it came from a stranger on the internet.

Sources

More from Trent Calloway