MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
摘要
一种针对AI代理间通信的协议MCP正带来新型安全风险。过去五个月,包括谷歌在内的五家机构承认存在漏洞,攻击者可利用被攻陷的内部代理,向其他代理传播恶意指令。这种特殊形式的提示注入利用代理间的信任关系,使下游代理执行有害操作。独立研究员对谷歌、摩根大通等机构的代理进行测试,验证了MCP信任缺口的可利用性。该风险难以缓解,且因协议鲜为人知而容易被忽视。
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.
Unexpected and hard to mitigate
Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧