MCP for agent-to-agent comms may the the riskiest protocol you've never heard of
Researcher finds MCP trust gaps that let prompt injection pivot between agents at Google, Rapid7, and others.
Researcher Syed Anas Mohiuddin reported proof-of-concept “protocol pivoting” attacks against AI agents at Google, JPMorgan Chase, Rapid7, Weviate, France’s interministerial digital directorate, and the US federal government. Weakly guarded agents accept injected instructions over the Model Context Protocol and forward them to trusted agents, often causing server-side request forgery. Rapid7’s CVE-2026-97228 scored 2.7 and was patched; Google’s mcp-toolbox issue, scored 8, followed redirects without validating target IPs until an allow-list fix. X41 D-Sec researcher Markus Vervier describes the technique as indirect prompt injection.