MCP 的 Agent 间通信被发现有结构性缺陷
A structural flaw found in MCP-based agent-to-agent communication
Ars Technica 报道,Google 等公司的 Agent 里存在的漏洞暴露出 MCP(Model Context Protocol,模型上下文协议)在 Agent 间通信上的结构性问题,记者称它可能是「你没听说过的最危险的协议」[1]。它要解决的问题被长期忽略:MCP 设计初衷是让 Agent 访问工具,而当它被拿来做 Agent 之间的消息通道时,信任边界就从「可信工具」变成了「不可信对端」,权限、来源与内容都失去了默认保证。对已经或准备用 MCP 做多 Agent 编排的团队,值得借鉴的是把对端当作不可信输入处理:校验来源、隔离权限、对返回内容做注入检测;限制是目前披露的是具体实现漏洞,协议层面的修法尚未定论,影响范围需要按自家部署逐项核实。
Ars Technica reports that vulnerabilities in agents from Google and others expose a structural problem with MCP (Model Context Protocol) when it is used for agent-to-agent communication, calling it possibly the riskiest protocol you have never heard of[1]. The overlooked issue: MCP was designed for agents to reach tools, but when it becomes a message channel between agents, the trust boundary shifts from a trusted tool to an untrusted peer, and origin, permissions and content lose their default guarantees. For teams already orchestrating multi-agent systems over MCP the transferable practice is to treat peers as untrusted input — verify origin, isolate permissions and scan returned content for injection; the limit is that what has been disclosed are implementation-level bugs, not a settled protocol fix, so exposure must be checked per deployment.