In my years of building, I’ve learned that a structure is only as strong as its joints. As we move from monolithic LLMs to multi-agent architectures, we are effectively building a palace with many rooms. However, recent vulnerabilities in the Model Context Protocol (MCP) reveal that while we’ve locked the front doors, we’ve left the hallways completely unguarded.
The Anatomy of Protocol Pivoting
I’ve been tracking a technique that researcher Syed Anas Mohiuddin calls "protocol pivoting." In a typical agentic workflow, a specialized agent (like one for translation) might receive a prompt. If that agent lacks robust guardrails—which many do—an attacker can use a prompt injection to hijack it. Because subsequent agents in the chain explicitly trust the first one, the malicious instructions spread through the network like a fire through a wooden scaffold.
The technical root lies in the Model Context Protocol (MCP), the standard used for communication between AI apps and internal agents. When an exploit bypasses the LLM's initial filters, it can succeed at the agent level because MCP servers store credentials for each specific tool. In the case of Google’s recent severity 8/10 vulnerability, the flaw was found in an MCP toolbox for databases. It initialized its HTTP client without a CheckRedirect policy and failed to validate target IP addresses, leading to Server-Side Request Forgery (SSRF).
The Death of Zero Trust
As a builder, I find the abandonment of "Zero Trust" principles in AI engineering deeply concerning. We are rushing to connect agents to our most sensitive databases without requiring authorization for transactions between nodes. As Douglas McKee of Rapid7 aptly put it, each protocol is checking its own front door while nobody watches the hallway in between.
Independent research tested these concepts and found that even diverse organizations—from government bodies to financial giants like JP Morgan Chase—have fallen into this trap. The fix isn't just a patch; it's an architectural shift. For example, Google’s remediation involved applying strict allow-lists of IP ranges and block lists. We must treat every interaction between agents as a potential threat vector.
Practical Recommendations for Architects
- Implement IP Validation: Never allow an MCP toolbox to make unauthorized network requests without validating target IPs.
- Enforce Redirect Policies: Ensure HTTP clients are configured with a
CheckRedirectpolicy to prevent SSRF. - Rebuild the Hallways: Move away from implicit trust. Every agent in a chain should verify the integrity of the data it receives from its predecessor.