Ars Technica · AI· Dan Goodin·· 4 天前AI 评分67
研究称 MCP 代理间通信存在结构性漏洞,Google 等机构产品受影响
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
AI 导读
独立研究者 Syed Anas Mohiuddin 公布了针对 Google、JP Morgan Chase、Weviate、Rapid7 及法、美两国政府机构 AI 代理的 PoC 攻击,利用 MCP(Model Context Protocol)中代理间信任链传递恶意提示词,使一个被入侵的代理把指令转发给下游代理,引发数据外泄等风险。
来源:Ars Technica · AI · arstechnica.com