Home / News EN / MCP and AI Agents: Data Security Risks for Users

MCP and AI Agents: Data Security Risks for Users

MCP AI agent security. Recent research has highlighted how malicious instructions can spread between artificial intelligence agents through internal trust relationships. The tests conducted raise questions about the security of integrations based on the Model Context Protocol (MCP) and potential risks to databases and confidential data.

MCP AI agent security

Independent researcher Syed Anas Mohiuddin created demonstrative attacks capable of exploiting trust between software components to circulate harmful instructions. The research highlights possible consequences, including unauthorized network requests and the theft of corporate or personal information.

MCP AI agent security: why it matters

Born as an open standard for the artificial intelligence ecosystem, MCP acts as a universal connector between language models and external resources. The protocol defines a shared architecture that allows AI agents to interact in a standardized way with software tools, databases, APIs, and local environments, enabling them to retrieve information, exchange context, and execute actions within complex workflows.

According to Mohiuddin, the entry point is represented by a specialized agent, for example one focused on translation or data analysis. If this component interprets hostile content as an instruction to be executed and forwards it, the next agent might accept it considering the sender reliable. This internal handover thus grants apparent legitimacy to a request controlled by the attacker.

This is a form of prompt injection that exploits the work organization between agents. In the described cases, the protections of specialized components are insufficient or absent: a command that the language model would have rejected can therefore find an alternative path through the system. The weakness emerges when one agent delegates a task and the next relies on the origin of the request.

Mohiuddin examined agents from various organizations, including Google, JPMorgan Chase, and Rapid7, as well as the French interministerial digital direction and the US federal government. The list describes the scope of the tests without demonstrating that every environment presents the same exploitation conditions. The material concerns attack proofs and vulnerabilities, and does not document actual data thefts at these organizations.

One of the described consequences is server-side request forgery (SSRF): the attacker induces a server to make unauthorized network requests. The manipulated instruction thus ceases to be merely text and produces an operation through an infrastructure component.

What Changes and What Are the Effects

Credential management also weighs on the risk. In the illustrated scenarios, MCP servers store credentials associated with agents, while internal components recognize each other as reliable. This combination allows a hostile instruction to exploit accesses already available in the system, with possible effects on databases and sensitive information managed by applications.

A concrete finding comes from Google’s official repository. The SSRF fix, integrated into mcp-toolbox on June 18, 2026, and cited by ArsTechnica, addresses a high-severity vulnerability in the HTTP source implementation and attributes the report to Mohiuddin. The intervention introduces SSRFGuard, a protection against DNS rebinding attacks, along with options to regulate access to private networks and define allowed or blocked IP ranges. The change also adds an initial verification of the base URL, so as to reject an insecure configuration during initialization.

This is an intervention on the behavior of the software that makes requests: the protection must act even when an agent has already processed and transmitted an instruction. The case suggests an essential distinction in evaluating agent security: model protections and those of connected services cover different steps of the same operation.

The described results challenge automatic trust between components, but do not demonstrate that any MCP implementation is vulnerable: the controls present, available credentials, and operations each agent can delegate count.

Source and further reading on MCP AI agent security: original article.

* Content created with the assistance of artificial intelligence systems.