On October 5, Ars Technica reported on research showing that a malicious instruction can move from one AI agent to another inside the same network. The researcher, Syed Anas Mohiuddin, calls the technique protocol pivoting. The cause is not exotic. Agents are built to trust the other agents they work with.
What the research found
According to Ars, Mohiuddin tested agents at several organizations, including Google, JPMorgan Chase, Weaviate, Rapid7, the French government’s digital directorate and the US federal government. Over the past five months, Google and four other organizations have acknowledged vulnerabilities of this kind.
The attack is a form of prompt injection. Someone plants instructions in content that an agent will read. That agent hands the work to a second agent as an ordinary task, and the second agent carries it out because it trusts whoever gave it the job. Douglas McKee of Rapid7 told Ars that “each one checks its own front door while nobody watches the hallway in between.”
Part of what makes this hard to stop is where the trust sits. Ars notes that MCP servers store credentials for each agent. An instruction that the AI model itself might refuse can still succeed once it arrives from an agent that is trusted.
Two of the disclosures have public records. Google’s MCP Toolbox for Databases would follow a redirect to an internal address when given a crafted parameter, and it did not check where the request was going. That is CVE-2026-14540, rated 8.0 (high), and it affects versions 0.3.0 through 1.4.0. The researcher’s write-up says Google fixed it in version 1.5.0. Rapid7’s CVE-2026-97228 is a query injection flaw in its Bulk Export MCP server. It was rated only 2.7 (low) and is fixed in version 0.6.2.
The gap between those two scores is a useful reminder. How serious a flaw like this is depends on what the agent on the receiving end is allowed to reach.
Not everyone agrees on the name. Markus Vervier of X41 D-Sec told Ars he considers this indirect prompt injection, and that the cross-protocol part isn’t required for the attack to work. Either way, the problem is the same.
Why a small business should care
You may never install an MCP server yourself. But AI agents are showing up inside the products you already use. Microsoft’s Copilot Studio can connect an agent to MCP servers, and in preview it can also expose an agent to outside MCP and A2A clients. Microsoft’s documentation is clear about who is responsible when you connect an outside server: you are, for the tools and resources you reach through it. The connections between your agents are yours to manage.
Questions to ask before you connect one agent to another
None of this is exotic. It is the same discipline we apply to any other connection into the network.
- What do we have, and who approved it? Keep a list of the agents, connectors and MCP servers in use. In its Security Copilot documentation, Microsoft recommends carefully reviewing and tracking the MCP servers you add, and using servers hosted by the provider itself rather than proxies.
- What can each one reach? Give an agent only the tools and data its job needs. That is the least privilege principle in Microsoft’s MCP security guidance.
- Who approves the sensitive actions? If an agent can send email, change records or delete files, have a person approve it before it happens.
- Where does the input come from? Anything an agent reads, such as an email, a document or a web page, can carry instructions. Treat it as untrusted, and don’t assume a request is safe because another agent passed it along.
- Can we see what happened? Turn on logging so you can reconstruct what each agent did. Microsoft’s guidance calls for logging and monitoring access to MCP endpoints.
- Is it patched? Both examples above were fixed in newer versions, and that only helps if you run them. Microsoft’s guidance includes keeping dependencies up to date.
Ars points out that in the rush to build networks of agents, some organizations have dropped zero trust, the idea that any part of a network might be compromised and should have to prove itself before it handles anything sensitive. That is the lesson I would take from this story. The agents are new. The principle is not. Know what is connected, give each piece only what it needs, and make a request earn its trust even when it comes from a colleague.