Ars Technica · AI· Dan Goodin·· 2 小时前AI 评分65
MCP 智能体间通信或存在高风险,信任缺口可传播恶意指令
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
AI 导读
过去五个月,Google 等五家机构承认存在可利用 AI 智能体向其他内部智能体传播恶意指令的漏洞。独立研究员 Syed Anas Mohiuddin 测试了包括 Google、JP Morgan Chase、Weviate、Rapid7 在内的多家机构,发现攻击利用了 MCP 中的信任缺口;这种提示词注入针对特定智能体,而非 LLM。
来源:Ars Technica · AI · arstechnica.com