Attackers can exploit trust between AI agents to spread malicious instructions and force systems to access restricted services. This scenario was described by independent security researcher Syed Anas Mohiuddin, according to infohub.kz.
AI agents are programs that perform tasks using external tools — for example, searching for information or working with databases. The MCP protocol is used to connect such tools.
An attack can begin with a malicious instruction hidden in a document or other material. One agent reads it and passes it to another as a routine work task. The second trusts the first and executes the attacker's command.
If the connected tool is poorly protected, this can force the server to access the company's restricted resources. As a result, there is a risk of access to internal services and confidential data.
According to Mohiuddin, similar vulnerabilities were confirmed and fixed in projects at Google, JPMorgan Chase, Weaviate, the French digital service DINUM, and the administration of the Indonesian city of Tangerang.
The researcher also reported possible issues in five systems for U.S. federal agencies. At the time of his report's publication, these reports were still being verified.
One of the most serious flaws was found in Google's database tool. Its severity was rated 8 out of 10. The server could follow spoofed addresses and send requests to internal resources. Google fixed the issue by adding address checks and access restrictions.
Another flaw was discovered in Rapid7's tool: unverified data allowed queries to the service to be altered. It was rated 2.7 out of 10 and also fixed. However, the flaw did not grant access beyond the permissions of the account in use.
The researcher recommends verifying AI agent requests and limiting tools' access to internal resources. Even if a command is passed by another program within the company, that does not mean it is safe.


