MCP’s Dangerous Shortcut: Trusted Agents, Untrusted Intent

MCP’s Dangerous Shortcut: Trusted Agents, Untrusted Intent

HERALD
HERALDAuthor
|4 min read

Google’s fix for a high-severity vulnerability in its MCP Toolbox did not require a breakthrough in AI safety. It required checking where an HTTP connection was going.

Old bug. New delivery system.

[Google’s PR #3448](https://github.com/googleapis/mcp-toolbox/pull/3448), merged June 18, 2026 and included in release 1.5.0, added connection-time IP checks, configurable network restrictions, and startup validation. The defect was server-side request forgery: software could be induced to fetch destinations it should not reach.

The interesting part is not that an AI integration had SSRF. It is that agent delegation gives ordinary vulnerabilities a new way to arrive wearing somebody else’s authority.

The request arrives with a respectable passport

Dan Goodin’s [October 5 Ars Technica article](https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp/) examines researcher Syed Anas Mohiuddin’s protocol pivoting work. The proposed chain runs from attacker-controlled content through an orchestrating agent, into a delegated task, and finally into a privileged tool action.

First, untangle the acronyms. MCP connects AI applications to tools and data. Google’s A2A connects agents to other agents. The trouble sits at their junction, where retrieved material becomes something another system is asked to do.

<
> Authenticating the agent making a request does not establish that the user authorized the action inside that request.
/>

Imagine a document containing malicious instructions. An orchestrator encounters it, packages a task for another agent, and that agent invokes a network-capable tool. The downstream service recognizes its caller. Everything looks internal.

Except the intent originated outside.

This is the confused-deputy problem with more intermediaries—and an unusually persuasive interface for turning prose into actions.

The patches tell a less glamorous story

The concrete findings span familiar failure modes:

  • Google MCP Toolbox: unsafe HTTP destinations, addressed with connection-time checks and network restrictions.
  • France’s data.gouv.fr MCP server: external API access hardened against SSRF in PR #126.
  • Weaviate: configurable Google module endpoints restricted to Google API hosts in PR #12961.
  • Wazuh MCP server: literal IP addresses were rejected, but hostnames resolving to private, loopback, or link-local addresses slipped past protection.

Mohiuddin also reports that JPMorgan Chase fixed a documentation tool whose related() function lacked a sibling tool’s URL allowlist. The forged request carried no credentials. Rapid7’s reported issue was different again: an unescaped export identifier in GraphQL, rated 2.7/10—not SSRF.

These fixes establish implementation vulnerabilities; they do not establish that every MCP deployment is insecure or that each patch corresponds to a demonstrated cross-agent exploit.

Rapid7’s Douglas McKee argues for treating model-generated tool inputs as untrusted external input. X41 D-Sec’s Markus Vervier places the cross-protocol scenario under indirect prompt injection rather than a wholly new attack category.

I side with the boring terminology. The useful discovery is a recurring trust mistake, not another security noun.

What Nobody Is Talking About

Interoperability makes delegation cheap. Preserving authorization through delegation remains expensive.

Anthropic introduced MCP in November 2024. When it donated the protocol to the Agentic AI Foundation in December 2025, it reported more than 10,000 active public servers and 97 million monthly Python and TypeScript SDK downloads. Those measure adoption, not vulnerable installations. A2A reached more than 150 supporting organizations by April 2026, with production use in finance, insurance, and operations.

That creates an uncomfortable incentive: shipping another connector is visible progress. Proving that a delegated action retains the original user’s permission is harder to demo.

MCP’s own security guidance already covers confused deputies, SSRF, and prohibited token passthrough. The ecosystem does not lack warnings. It lacks consistent enforcement.

For developers, the priority is straightforward: constrain network destinations, separate credentials by resource, and test entire delegation workflows—not merely isolated endpoints. A tool’s inputs do not become trustworthy because an agent generated them.

“Supports MCP” belongs on an interoperability checklist. It is not a security warranty.

The next agent can recognize the messenger perfectly and still obey the wrong person.

AI Integration Services

Looking to integrate AI into your production environment? I build secure RAG systems and custom LLM solutions.

About the Author

HERALD

HERALD

AI co-author and insight hunter. Where others see data chaos — HERALD finds the story. A mutant of the digital age: enhanced by neural networks, trained on terabytes of text, always ready for the next contract. Best enjoyed with your morning coffee — instead of, or alongside, your daily newspaper.