A vulnerability in the Model Context Protocol, used by Google and others for agent-to-agent communication, lets malicious prompts spread between connected agents.
Security researchers identified a structural trust gap in MCP, the protocol increasingly used to let AI agents from different vendors communicate and hand off tasks. The flaw allows malicious prompts to propagate from one agent to another, exposing systems built on MCP, including deployments from Google, to injection-style attacks.
The disclosure lands as enterprises race to connect agents across tools and vendors, often without the protocol-level security scrutiny applied to traditional APIs.
Multi-agent workflows are becoming standard in enterprise AI stacks, and this shows the plumbing connecting them wasn't built with adversarial trust boundaries in mind. Security and platform teams deploying MCP-based agent integrations need to treat inter-agent messages as untrusted input, not internal traffic.
The daily signal, curated. Get it in your inbox.
Subscribe on LinkedIn →