• 2 min read
AI connectors changed fast — and widened the risk surface
PromptArmor says connectors for ChatGPT and Claude are changing so quickly that security reviews can quickly go stale.

Image: The Register
Security reviews for AI connectors may be out of date almost as soon as they are finished. According to PromptArmor, integrations that link agents in OpenAI’s ChatGPT and Anthropic’s Claude to services like Gmail, Slack, and Dropbox are changing so quickly that governance assumptions can break in a matter of weeks.
The security company examined how connectors behave and found a high rate of change across the ecosystem. Over the six weeks from mid-May to the end of June, 931 of 2,517 connectors — 37 percent — changed. PromptArmor also recorded 1,686 new tools added to connectors that were already live, and 1,127 tool descriptions rewritten, changes that could alter when and how an AI model decides to invoke them.
Shankar Krishnan, PromptArmor co-founder, told The Register that enterprise adoption and the speed of connector updates are driving concern.
“For connectors, the risks are mostly about the type of tools, what they can do, where the data is going, and what is being done with the data.”
PromptArmor pointed to the Dropbox connector as an example. At the start of the study, it exposed eight tools; by the end, that had grown to 24. Write-capable tools rose from three to 10, while potentially destructive tools went from zero to four. The company also said permission scopes changed and instructions injected for the model were added.

Recommended reading
ServiceNow RCE flaw is now under active attack
A second concern is that connectors can pass data on to additional AI systems. PromptArmor evaluated 7,517 tools used by 487 Claude connectors and concluded that 189 connectors, or about 2 in 5, are likely to call extra AI services.
“The issue is that most teams approving connectors are evaluating and considering the connector – unaware that the vendor is calling more AI services, adding new subprocessors and terms.”
PromptArmor gave Zoom as an example, arguing that a sensitive natural-language search query sent through its connector could then be routed by Zoom AI to any of its ten AI subprocessors to generate a response from one of eight different model families.
Anthropic’s own documentation acknowledges the limits of its controls over third-party processing, noting that connected services handle data on their own infrastructure and under their own terms, potentially outside the United States. As Krishnan put it, once agents gain access to sensitive data, untrusted content, and external actions, “the blast radius of an attack explodes.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


