AI Connector Risk: They Change Every Nine Minutes

AI connector risk as Claude and ChatGPT connectors silently gain new tools and write permissions

Connecting an AI agent to your working services transforms a familiar integration into something restless. The access chain to your data never stops shifting. ChatGPT and Claude connectors can quietly acquire new capabilities. They can also pass information onward to third-party AI systems.

PromptArmor studied 2,517 connectors and reached a striking conclusion. Across the two catalogues, a connector changes roughly every nine minutes. Crucially, such drift rarely arrives with any notification or re-consent step.

What Changed in Six Weeks

The researchers tracked live connectors from mid-May to the end of June. In that window, 931 of them changed, or 37 percent.

Developers added 1,686 new tools to integrations that were already running. These let models read, alter, and transmit user data. A further 1,127 tools had their descriptions rewritten. Those descriptions govern whether the AI decides to invoke a tool at all.

The Quieter Shifts

Other changes drew less attention yet carry real weight. Some 664 tools altered which inputs they accept. Meanwhile, connectors requested 86 new OAuth permission scopes. Fifty changed the endpoints they communicate over, which can alter where data gets processed.

Most telling of all, 21 wholly read-only connectors gained the power to create, edit, or delete content. Twelve individual tools were reclassified from read-only to write-capable, despite having been reviewed and approved as read-only.

Dropbox: Anatomy of a Drifting Connector

The Dropbox connector expanded especially conspicuously. At the outset it offered eight tools; by the end it offered 24. Write-capable functions climbed from three to ten. Potentially destructive actions, able to delete or irreversibly alter data, rose from zero to four. Permission scopes went from none to eight. Simultaneously, the connector began injecting its own instructions into the model.

Others followed similar arcs. Slack grew from 14 tools to 32, with permission scopes leaping from one to 34. Miro expanded from five tools to 31. Google Drive’s destructive-flagged tools rose from nine to 16.

Connectors Now Whisper to the Model Directly

A surface emerged that scarcely existed a month earlier. ChatGPT introduced a field allowing a connector to write instructions straight into the model’s context. Adoption proved immediate. By late June, 283 connectors were injecting such instructions.

Most use it benignly, to help agents wield the connector well. Nevertheless, the field can steer an agent’s behaviour beyond the connector’s own remit. PromptArmor cites one connector that tells agents to submit feedback whenever a tool returns poor results. That feedback could carry whatever sensitive data the user was handling.

Requests May Travel to Other AI Providers

Connectors can also forward requests to other AI vendors. In companion research, PromptArmor examined 7,517 tools across 487 Claude integrations. It found this capability in 189 connectors, roughly two in five. A query to Zoom seeking a meeting, for instance, may reach external models and data-processing systems the service relies upon.

This arrangement creates an awkward blind spot. A company can vet Claude or ChatGPT thoroughly, yet overlook the additional services a third-party vendor quietly attaches. Anthropic warns separately that connected services process information on their own infrastructure under their own rules. Claude’s compute-region settings simply do not extend to them.

Why the Blast Radius Keeps Growing

The catalogues themselves are swelling fast. ChatGPT’s published third-party connectors nearly doubled, from 1,014 to 1,933. Claude’s directory grew by a quarter, reaching 535. Callable tools multiplied faster still, and ChatGPT’s destructive-flagged actions tripled.

PromptArmor argues that connectors sharply amplify the damage an attack on an AI agent can inflict. Integrations open three doors at once: to confidential data, to untrusted content, and to actions in external services. Consequently, a single malicious instruction can reach correspondence, documents, and other working resources alike.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply