← Back to overview

Protocol Pivoting: Why MCP Is Becoming the Most Dangerous Vulnerability in AI Agent Networks

Dr. Maik Bunzel
Dr. Maik Bunzel
08.10.2026 · 6 min read
Protocol Pivoting: Why MCP Is Becoming the Most Dangerous Vulnerability in AI Agent Networks

A Protocol That Connects AI Agents – and Opens the Door to Attackers

Anyone who has followed how rapidly companies have been integrating AI agents into their processes over the past few months may not yet have encountered the name MCP. The Model Context Protocol is the de-facto standard through which AI applications and autonomous agents communicate with one another within an internal network. It is the invisible nervous system behind modern Agentic AI architectures – and that is precisely why it is now at the center of a serious security debate.

Independent security researchers have uncovered vulnerabilities in agent implementations at organizations such as Google, JP Morgan Chase, and others over the past five months. The common thread: all use MCP – and all were susceptible to a new attack technique being discussed under the term Protocol Pivoting. The implications for companies building agent infrastructures today are significant.

What Is Protocol Pivoting – and Why Is It So Insidious?

Classic prompt injection aims to manipulate a Large Language Model through crafted inputs into producing harmful outputs. Protocol Pivoting goes one decisive step further: the attack does not target the LLM directly, but rather a specialized agent within the network – such as a translation or data analysis agent. This agent reads manipulated content, treats it as a legitimate instruction, and delegates it – entirely through normal channels – to the next agent in the chain.

What makes this so insidious: the second agent implicitly trusts the first, because MCP servers store credentials for each agent and agents are by design built to trust internal peers. An instruction that an LLM would have rejected outright passes through the internal network unimpeded – often crossing protocol boundaries, for example from MCP to Google's Agent-to-Agent protocol (A2A).

„AI agents give attackers a fresh set of connections to walk across. Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work." — Douglas McKee, Rapid7

The results can be severe attacks: Server-Side Request Forgery (SSRF), exfiltration of database contents, access to sensitive business and personal data. The vulnerabilities examined ranged from low severity (2.7/10 at Rapid7) to critical values (8/10 at Google), where a flawed HTTP client without a CheckRedirect policy and without IP validation allowed attackers to target internal endpoints.

The Structural Problem: Zero Trust Was Forgotten

Anyone who examines the architecture of modern agent networks recognizes the fundamental dilemma: in the race to roll out automation solutions as quickly as possible, many organizations have set aside a decades-old security principle – Zero Trust.

Zero-trust architectures assume that any node in the network could be compromised. Therefore, every transaction – even between internal systems – must be explicitly authorized. In hasty Agentic AI rollouts, however, agents are often configured to trust one another unconditionally. McKee describes the consequence aptly: Every part of the chain did exactly what it was built to do. That is precisely what makes the attack so difficult to detect.

Dr. Maik Bunzel, founder and managing director of mabucon.eu, regularly emphasizes in his consulting practice that the speed of agent adoption is frequently in a dangerous disproportion to the maturity of the security concepts deployed. Organizations that today operate multiple specialized AI agents within their process chain must ask themselves: Which agents trust which – and on what basis?

Why MCP is particularly exposed

MCP is new and already widely adopted – before it has been sufficiently tested and hardened. That is the real structural problem. Individual protocols are typically designed and secured for their own context. In complex agent architectures, however, multiple protocols converge: MCP for internal agent communication, A2A for inter-agent delegation, and further emerging standards such as the Agent Network Protocol. At the transitions between these protocols, a grey area emerges in which authorization and trust checks are effectively lost.

  • Missing Guardrails: Many specialized agents have barely any built-in protection mechanisms against Prompt Injection, as their function is designed for efficiency rather than mistrust.
  • Implicit trust: MCP servers store credentials for each agent and rely on internal trust – an attack vector that proves fatal when faced with external threats.
  • Cross-protocol blind spots: Security checks often only apply within a single protocol; the transition to another protocol is not re-evaluated.
  • Rapid growth without standardization: The proliferation of newly emerging agent standards makes it increasingly difficult to enforce uniform security policies.

Familiar attack patterns, new stage

It is important to put the threat in its proper perspective: the technical building blocks of Protocol Pivoting – injection attacks and SSRF – are not new inventions. They have occupied the security industry for two decades. What has changed is the stage: AI agents create a new attack surface on which well-known vulnerabilities can be exploited with renewed effectiveness.

Security researcher Markus Vervier of X41 D-Sec classifies Protocol Pivoting as a subcategory of indirect Prompt Injection. The term "Protocol Pivoting" nonetheless has its value: it gives defenders and standardization bodies a concrete concept for which they can develop targeted countermeasures. A name is often the first step toward systematic defense.

What organizations need to do now

The insights from these security analyses can be translated into concrete recommendations for action that every organization with agent-based AI infrastructure should take seriously:

  • Apply the Zero-Trust principle at the agent level: Every agent-to-agent call should be treated as potentially untrusted and explicitly authorized – regardless of its position within the internal network.
  • Input validation at every protocol boundary: Everything an agent receives from another agent or LLM must be treated as external, untrusted input.
  • Implement SSRF protection for all MCP servers: IP allowlists, URL validation at startup (not just on the first request), and CheckRedirect policies are not optional – they are minimum standards.
  • Document and audit agent communication paths: Which agent communicates with which, via which protocol, and with which permissions? Without this transparency, systematic security hardening is impossible.
  • Introduce security testing for agent chains: Classic penetration tests must be extended to include agent-specific scenarios that deliberately stress-test protocol transitions and trust chains.

Dr. Maik Bunzel, founder and managing director of mabucon.eu, sees in these developments a clear mandate for organizations that want to deploy AI agents strategically: security architecture must not be an afterthought. Anyone designing agent workflows today must incorporate trust models, protocol boundaries, and authorization mechanisms from the very beginning – not as a retroactive patch.

Outlook: Security as a Competitive Advantage in the Age of Agents

MCP and related protocols will continue to evolve and are likely to be hardened over time – the fixes by Google and Rapid7 demonstrate that the organizations involved are capable of acting decisively. Yet the real challenge lies not in individual patches, but in a cultural and architectural shift: Agentic AI requires a security mindset that keeps pace with the complexity of distributed, cross-protocol systems.

For organizations, this presents a strategic opportunity: those who build agent infrastructures with security in mind from the outset gain not only protection against attacks, but also trust from customers, partners, and regulators. In a world where autonomous AI systems are becoming ever more deeply embedded in business processes, the ability to operate these systems securely will become a genuine differentiator.

Awareness of Protocol Pivoting and related attack vectors is the first step. The consistent implementation of Zero-Trust principles at the agent level is the second. And the continuous review of growing agent chains is the third – and most enduring.

Contact

Which of your workflows should become smarter first?

Briefly describe the process you would like to support or replace with AI. We will get back to you with a first, concrete assessment — no obligation and confidential.