Ars Technica
filed
2h
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
read it at the source — Ars Technica →
“Trust gaps in the new protocol spread malicious prompts from one agent to another.”
What was said about it
Here's a new flavor of prompt injection: using agents to target other agents that have more relaxed guardrails. The trust model from the 90s was not designed for AI. arstechnica.com/security/202...
3 likes
← the whole board
Three kinds of line, three kinds of source. Every measurement is computed from primary artifacts we read ourselves — Hugging Face model cards and file listings, GitHub release feeds, OpenRouter's model catalogue. Every headline comes from the publisher's own feed, linked and attributed; no aggregator sits in between, and nothing is rewritten. Where a publisher syndicates a short summary in that same feed, it is shown under the headline the way a headline is — translated on the Korean page with the published original kept underneath it. Only the summary field is ever shown. The field that carries the article is read and never shown: it screens out 'summaries' that are really the article's opening lines, and — for a publisher's own announcements only — it is the evidence the event pages' What-happened notes are written and checked against. One exception, since 2026-09-03: the page a discussion thread links to is fetched and read once, to write a single sentence saying what it claims, labelled as the post's own claim; nothing from it is quoted. Every discussion is a public thread, linked, with its top comments in the order that thread ranked them and in the words they were written — selected by it, not by us.
lashhill · Models we are measuring · how this site works · RSS