The Problem with Agent Friend Groups

Lowkey, the way AI agents work right now is kind of wild. Companies are obsessed with setting up 'agentic architectures' where AI models do everything from analyzing data to writing code. To make this work, they use something called the Model Context Protocol (MCP) to let these agents talk to each other.

But here’s the plot twist: this protocol is basically the ‘don’t ask, just trust’ version of networking. Independent researcher Syed Anas Mohiuddin found that this blind trust is a massive security loophole. Because these agents are built to trust whatever instruction comes from another agent, an attacker can plant a malicious prompt in one spot, and it spreads through the whole system like gossip in a high school cafeteria.

It’s Giving SSRF

When these agents aren't protected by tight guardrails, they end up doing exactly what they’re told—even if it means accidentally letting an attacker walk right into your internal database. This can lead to server-side request forgery (SSRF), where your own server starts making unauthorized requests for an attacker.

Douglas McKee, a vulnerability intelligence director at Rapid7, explained the vibe: 'Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task.' Because every piece of the chain is doing its job correctly, it’s lowkey hard for security teams to catch the problem before it’s too late.

The “Protocol Pivoting” Mess

Mohiuddin is calling this ‘protocol pivoting.’ Essentially, an attacker gets in through one door (like MCP) and then switches to another, like Google’s Agent-to-Agent (A2A) protocol, to move around your network. It’s a multi-step mission that leaves security teams playing catch-up. Google already had to patch a vulnerability (rated 8 out of 10) in their MCP toolbox that let attackers send requests on their behalf.

Why it matters

The industry is in such a rush to automate everything that they’ve basically abandoned ‘zero trust’—the idea that you shouldn't trust any part of your network, even the stuff inside. Real talk: any input from an LLM should be treated like a random DM from a stranger. Until companies stop assuming their AI friends are always telling the truth, these systems are going to stay wide open for exploitation. The bugs might be new-gen AI, but the solutions are just the old-school security basics we've needed for decades.