Ars Technica AIT2·78 pts
MCP Protocol Vulnerable to Cross-Agent Prompt Injection Attacks
Original: MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
- The MCP protocol is vulnerable to cross-agent prompt injection, allowing attackers to propagate malicious instructions from one agent to trusted downstream agents.
- Existing guardrails within agents are often lax or missing, failing to intercept malicious payloads from upstream trusted sources.
- Multiple organizations including Google and JP Morgan have confirmed this risk, indicating it is a real-world threat rather than a theoretical assumption.