Executive Overview
The rapid, unbridled enterprise adoption of autonomous artificial intelligence agents has opened a Pandora’s box of novel security vulnerabilities. As millions of organizations race to integrate agentic workflows—such as automated translation, database querying, and code generation—into their operational backbones, malicious actors are capitalizing on foundational flaws in how these systems communicate.
Over the past five months, independent security researchers and major technology corporations, including Google, have acknowledged critical vulnerabilities rooted in a dangerous architectural assumption: that internal AI agents can implicitly trust one another.
A newly identified attack vector, dubbed "protocol pivoting," leverages trust gaps within the Model Context Protocol (MCP)—the emerging standard that governs how AI apps and internal network agents converse. By injecting malicious instructions into a target network via a low-privilege or auxiliary agent, an adversary can cascade harmful directives down a chain of fully trusted, specialized internal agents. Because these downstream agents operate under the assumption that any command handed to them by a peer is legitimate, they execute unauthorized actions. This can lead to severe operational compromises, including the exfiltration of sensitive business information, personal records, and database contents, alongside devastating server-side request forgery (SSRF) attacks.
This investigative report delves into the mechanics of protocol pivoting, examines the systemic failures of modern agentic network design, outlines major vulnerabilities discovered across prominent tech platforms and government agencies, and provides expert insight into how organizations can reclaim zero-trust principles before their AI infrastructure becomes their greatest liability.
Detailed Chronology and the Mechanics of "Protocol Pivoting"
The genesis of this threat lifecycle traces back to the rapid proliferation of the Model Context Protocol. Designed to streamline communication between disparate AI applications and internal databases, MCP serves as the invisible connective tissue of modern agentic architectures. However, in their rush to deploy sprawling automation networks, enterprise engineers largely bypassed foundational security paradigms, neglecting to implement rigorous authentication or validation steps between nodes.
The Anatomy of an Attack
The mechanics of a protocol pivot exploit a multi-step escalation chain:
- Initial Vectoring (Indirect Prompt Injection): An attacker introduces malicious instructions into an external data source that an organization’s AI agent is programmed to read—such as an incoming email, a public web page, or an unvetted document repository.
- The Hand-Off: The first agent processes the tainted data and treats the hidden, malicious text as a valid delegated task. Because special-purpose agents (like translation or parsing modules) frequently lack robust local guardrails, the agent packages the malicious payload and forwards it to another internal agent down the chain.
- Protocol Translation and Trust Exploitation: As the instruction crosses boundaries—frequently transitioning from MCP to alternative frameworks like Google’s Agent-to-Agent (A2A) protocol—authorization checks are often lost in translation. The receiving agent reads the command, verifies that it originated from a trusted internal peer, and executes it without hesitation.
- Impact Manifestation: The final node in the chain performs the requested action, which may involve querying internal database endpoints, leaking confidential files, or executing a server-side request forgery (SSRF) attack that forces the internal server to interact with malicious external infrastructure.
Independent security researcher Syed Anas Mohiuddin brought these systemic flaws to light after testing agentic systems across a diverse array of high-profile entities, including Google, JPMorgan Chase, Weaviate, Rapid7, the French government’s interministerial digital directorate, and various arms of the United States federal government. Mohiuddin’s proof-of-concept exploits highlighted that these organizations shared virtually nothing in common—except for their reliance on MCP and their blind adherence to internal trust assumptions.

Supporting Context, Metrics, and Case Studies
To understand the severity of protocol pivoting, one must examine the specific vulnerabilities uncovered by researchers and the systemic architecture that allowed them to flourish.
Rapid7 and CVE-2026-97228
In the case of cybersecurity firm Rapid7, Syed Anas Mohiuddin discovered a vulnerability cataloged as CVE-2026-97228. Though assigned a relatively modest severity rating of 2.7 out of 10 by standard scoring metrics, the bug exposed the inherent fragility of multi-agent delegation chains. Rapid7 moved swiftly to patch the vulnerability, but the incident underscored a chilling reality: even companies whose core business is security can stumble when integrating autonomous agent frameworks that lack inter-node verification.
Google’s Database Toolbox Vulnerability
A far more severe manifestation of the flaw was discovered within Google’s infrastructure, carrying a CVSS severity rating of 8.0.
The vulnerability stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) that initialized its underlying HTTP client without implementing a CheckRedirect policy. A CheckRedirect policy comprises the critical settings that dictate how a web server must respond when a URL returns an error or redirects traffic to an alternate destination. Compounding this oversight, Google’s HTTP client failed to adequately validate target IP addresses.
Explaining the mechanics of the exploit, Mohiuddin noted:
"A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf."
Google mitigated the risk by instituting a strict allowlist of IP ranges alongside comprehensive blocklists, ensuring that unsafe base URLs are rejected at system startup rather than upon the arrival of the first runtime request. Security experts lauded this as an example of a proper, robust SSRF defense—while noting that it required a level of engineering rigor far beyond what most current MCP server deployments undergo.

The Debate Over Nomenclature
While Mohiuddin coined the term "protocol pivoting" to describe multi-step attacks that leverage trust assumptions across differing communication protocols, other industry veterans argue the phenomenon is simply an advanced subclass of an older, familiar threat.
Markus Vervier, a senior researcher at security firm X41 D-Sec—who has previously uncovered critical vulnerabilities in open-source AI agent packages—maintains that the core issue remains indirect prompt injection.
"For me, this is indirect prompt injection," Vervier noted. "The fact that the malicious prompt can come from a different protocol (e.g., A2A) and manifests when used over another protocol is not strictly required for such attacks to work. It is, of course, unexpected and hard to mitigate in general."
Official Statements and Industry Perspectives
The cybersecurity community has responded to the disclosure of protocol pivoting with a mixture of professional recognition and profound concern over the state of enterprise AI engineering.
Douglas McKee, Director of Vulnerability Intelligence at Rapid7, offered a vivid analogy for the systemic architectural flaw during an interview:
"AI agents give attackers a fresh set of connections to walk across. Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between."
McKee emphasized that the underlying software bugs—injection flaws and SSRF—are decades-old vulnerabilities whose mitigation strategies have been well-understood for twenty years. The danger lies not in the novelty of the code errors, but in the reckless abandonment of foundational security principles by organizations rushing to deploy artificial intelligence.

"The lesson I’d want people to take away is that anything passed from an LLM to your tool should be treated like input from a stranger on the internet, because in a prompt injection scenario that’s exactly what it is," McKee added. "Credit to the researcher for putting a name on it, because a name is what gets defenders and standards bodies to actually design for it."
Future Outlook: Rebuilding Zero Trust in the Age of Autonomous Agents
The emergence of protocol pivoting serves as a glaring wake-up call for the enterprise technology sector. As organizations scale their investments in multi-agent architectures, the traditional perimeter-based security model has proven woefully inadequate.
To prevent systemic compromises, security architects must return to the foundational tenets of Zero Trust, a philosophy dictating that networks must always assume nodes are potentially compromised and that no entity—human or synthetic—should enjoy implicit trust.
Key Recommendations for Enterprise Defense:
- Granular Inter-Agent Authentication: Enterprises must implement cryptographic identity verification and token-based authorization for every message passed between autonomous agents, ensuring that instructions cannot be executed merely because they arrived via an internal channel.
- Rigorous Input Sanitization at Every Tier: Downstream agents must never trust upstream inputs implicitly. Every prompt received from a peer agent must undergo the same rigorous sanitization, context verification, and security screening applied to raw external data originating from the open internet.
- Hardened Protocol Gateways: As organizations bridge disparate communication standards (such as MCP and A2A), cross-protocol gateways must enforce strict allowlists, validation policies, and redirect controls to eliminate Server-Side Request Forgery vectors.
- Standardization and Governance: Standards bodies and open-source maintainers must prioritize security-by-design in emerging agent protocols, moving past the "move fast and break things" paradigm that currently characterizes the generative AI ecosystem.
Unless organizations fundamentally overhaul how they govern inter-agent communication, protocol pivoting will likely evolve from an advanced researcher’s proof-of-concept into an automated, widespread weapon used by threat actors to quietly hollow out enterprise networks from the inside out.
