MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Model Control Protocol — the plumbing that lets agents talk to each other — has a structural flaw that spreads malicious prompts like a worm. Google and others are exposed.

Why it matters
MCP, the emerging standard for agent-to-agent communication, lacks trust boundaries between agents, allowing a compromised or adversarial agent to inject malicious prompts into downstream agents. This is a foundational security gap in the agent infrastructure layer, not a patch-able bug — it requires rethinking how agents validate and sandbox inbound communication.
The key facts
6 to knowMCP (Model Control Protocol) used by Google and other vendors
Vulnerability allows malicious prompts to propagate agent-to-agent
Trust gap is structural, not a single bug
Published by Ars Technica security reporting
Affects multi-agent orchestration architectures in production
No vendor-specific exploit details provided in headline
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: Trust gaps in the new protocol spread malicious prompts from one agent to another.