Over the past five months, Google and four other organizations have acknowledged vulnerabilities in AI agents that let one agent spread harmful instructions to other internal agents. The attacks exploit trust gaps in the Model Context Protocol (MCP), a standard used for agent-to-agent communication inside networks. Independent researcher Syed Anas Mohiuddin demonstrated proof-of-concept attacks against agents from Google, JP Morgan Chase, Weaviate, Rapid7, and government organizations.

The technique is a form of prompt injection that targets a specific agent rather than the LLM itself. Because MCP servers store credentials and agents are built to trust other internal agents, a well-crafted prompt can lead to server-side request forgery. Mohiuddin calls the class of attack 'protocol pivoting' because malicious instructions move from MCP to other protocols such as Google's Agent-to-Agent (A2A). Rapid7's Douglas McKee says the attack is hard to catch because every component in the chain does exactly what it was designed to do.

Not everyone agrees on the name. Markus Vervier of X41 D-Sec argues the technique is simply a subclass of indirect prompt injection, not a new category. Both researchers agree, however, that the underlying flaws are old—injection and SSRF—and that organizations have abandoned zero trust in their rush to build agentic architectures. McKee advises treating anything passed from an LLM to a tool as untrusted input, as if it came from a stranger on the internet.