MCP agent-to-agent flaws expose missing protocol-level security
Security researchers found structural flaws in Anthropic's Model Context Protocol: it lacks caller identity, capability tokens and audit trails when one agent invokes another agent's tools. The disclosed vulnerability affected Google and other agent platforms, letting an agent act as a confused deputy to reach tools it shouldn't.
- MCP does not identify the calling agent or scope tool access
- Attack uses a target agent as a confused deputy for unauthorized resources
- Protocol lacks capability tokens, audit logging and per-agent rate limits
- Google and other agent platforms affected by the structural gap
Read next
Security