AI news · October 7, 2026
Researchers warn that agent handoffs can break MCP trust boundaries
Agent protocols can expand an attack path when one trusted agent passes instructions to another. Treat every handoff as an untrusted boundary and validate destinations, identity, and tool authority.
Ars Technica reported on October 5 that researcher Syed Anas Mohiuddin found a recurring trust problem in agents connected through the Model Context Protocol and related agent-to-agent systems. The report describes protocol pivoting: a malicious instruction moves from an upstream agent into a downstream agent that trusts the request, then uses the second agent's tools or network position. The cases span cloud, finance, security, and government systems.
The report says one Google case was rated severity 8, while Rapid7 assigned CVE-2026-97228 a lower 2.7 rating and patched it. Google described fixes including allow-listed IP ranges, block lists, and rejection of unsafe base URLs at startup. These reports do not prove that every MCP integration is exploitable or that a breach occurred.
The design lesson is direct. A tool call that arrives through another agent must not inherit trust from the transport alone. The receiving system needs a clear identity, destination policy, user approval for high-impact actions, and logs that preserve the full chain from prompt to network request.
What you can do with it
Map every agent handoff and tool capability before launch. Enforce destination allow-lists, reject unsafe URLs, isolate credentials by agent, require approval for external side effects, and log the original instruction plus each delegated call. Add a test that tries to pivot through a trusted downstream agent.
Our take
This is a structural warning, not a reason to stop using protocols. The weak design is implicit trust: an agent trusts the next agent because it is connected. Builders that make identity, scope, and destination checks explicit can turn the flaw into a product advantage and a buyer-facing control.
Links Ars Technica report
Source: Ars Technica ↗ — Made With Models writes the brief; the reporting is theirs.