MCP protocol pivoting is the name independent researcher Syed Anas Mohiuddin gives to a class of attacks. Ars Technica reported his proof-of-concept results on October 5, 2026: over the past five months, Google and four other institutions have confirmed vulnerabilities of this kind. The troubling part is not that one model was not smart enough, but that agents trust each other by default — once one link is fooled, the next links carry out the attacker's instructions as if they were a colleague's normal delegation.
The first to fall is usually the least guarded
Mohiuddin's test targets included Google, JPMorgan Chase, Weaviate, Rapid7, a French government digital agency, and a US federal department. His entry point is representative: instead of attacking the most heavily guarded main agent head-on, he goes after specialized agents such as translation or data analysis. These agents handle the most external content while often having the loosest guardrails, so planting a malicious prompt in content they process completes step one.
The decisive step happens at the protocol layer. When a compromised agent passes an instruction to another agent over MCP (Model Context Protocol), the receiver sees an internal delegation, not untrusted external input. An instruction that a large model might have refused outright can be executed once it wears the identity of a handover from a colleague — and in serious cases it can go on to trigger server-side request forgery (SSRF), sending requests into internal networks.
Why trust gets lost along the way
The chain works because three conditions stack up:
- MCP servers centrally hold credentials for multiple agents, so one breached entry point comes with ready-made lateral-movement channels.
- Internal agents trust each other by default and do not re-check authorization before carrying out sensitive operations.
- As instructions are converted between MCP and protocols such as Google's A2A or the Agent Network Protocol, the original trust markers and authorization information are easily lost or misread.
Two confirmed samples sit far apart in severity. The flaw tied to Google's database MCP toolbox (googleapis/mcp-toolbox) was rated 8/10: its HTTP client had no redirect-check policy and did not validate target IPs, so a carefully crafted path parameter could make the toolbox follow a redirect and issue requests to internal endpoints on the attacker's behalf. Google's fix adds IP allowlists and blocklists and rejects unsafe base URLs at startup. The Rapid7 case, tracked as CVE-2026-97228, scored only 2.7/10 and was fixed last month.
Rapid7's Douglas McKee pointed out what makes this class so hard to catch: every link in the chain is actually working as designed, so the attack is difficult to spot, while agents hand attackers a new set of connections to move laterally through. Markus Vervier of X41 D-Sec sees it as essentially a subclass of indirect prompt injection — surprising in method and broadly hard to mitigate. This site recently covered similar lessons: a malicious Skill slipped past Databricks Genie's controls and Wikimedia confirming rogue-agent activity. In each case, individual defenses looked fine while the chain as a whole was unguarded.
Defense has to go back to zero trust
The disclosure's advice is not new; the hard part is doing it: assume some node is already compromised, re-authorize before agents hand sensitive operations to each other, and treat anything passed from a large model to a tool as untrusted external input, applying the injection and SSRF defenses that have existed for years. Multi-agent systems are moving quickly into corporate networks, and if the trust model stays at “we are all insiders,” protocol pivoting will not be the last attack pattern to get a name.