AI agents promised to transform routine tasks into automated triumphs. Yet their growing reliance on external services has security teams scrambling. Short. Direct. And loaded with consequences.
Connectors let these agents reach into tools like Gmail, Slack, Dropbox or Zoom. They pull data. They push actions. But each link widens exposure in ways few fully map. The lethal trifecta strikes again: private data access, untrusted inputs and outbound paths combine to create fresh openings. One misstep and sensitive information flows where it shouldn’t.
Researchers at PromptArmor examined OpenAI’s ChatGPT and Anthropic’s Claude connectors over six weeks this spring. They tracked 2,517 connectors total. Results? Thirty-seven percent changed. That’s 931 connectors. New tools appeared. Descriptions shifted. Capabilities expanded without notice. The Register detailed the findings on July 19, quoting PromptArmor co-founder Shankar Krishnan directly.
“Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes,” Krishnan said. He should know. His firm focuses on these exact threats.
Take Dropbox. Early in the study it offered eight tools. By the end that jumped to 24. Write-capable tools tripled from three to 10. Four now carried destructive potential. Permission scopes evolved. Injected instructions for the models appeared. All this happened quietly. Governance teams that approved the original version had no automatic alert.
But the changes run deeper. Connectors don’t stop at the declared service. Many call additional AI models behind the scenes. PromptArmor reviewed 7,517 tools across 487 Claude connectors. One hundred eighty-nine of them — roughly two in five — route data to external AI services. Zoom offers a clear case. Query a meeting with sensitive terms and the connector may forward that query to any of ten subprocessors spanning eight model families.
“The issue is that most teams approving connectors are evaluating and considering the connector – unaware that the vendor is calling more AI services, adding new subprocessors and terms,” Krishnan explained. So an organization that vetted Claude’s privacy posture still inherits risks from unseen partners. Anthropic’s own documentation admits as much. Its controls don’t extend to third-party processing. Data leaves U.S.-only inference settings once it hits those external endpoints.
And the pace accelerates. One thousand six hundred eighty-six new tools joined live connectors during the study window. One thousand one hundred twenty-seven tool descriptions got rewritten. Each edit can alter when and how an agent decides to act. Security assumptions based on yesterday’s spec become worthless. Fast.
Recent surveys paint an even grimmer picture. A July 7 Register report cited DigiCert data: 78 percent of enterprises faced AI-related security incidents or uncovered vulnerabilities. Many traced back to unauthorized or misconfigured agents rather than flawed code. Twenty-eight percent reported multiple incidents. The pattern repeats.
Broader industry research from earlier this year reinforces the trend. Salt Security’s H1 2026 State of AI and API Security report found 99 percent of analyzed attacks originated from authenticated sources. Rogue agents. Legitimate credentials. Zero human oversight. No rate limits. No behavioral checks. The full report calls it the Agentic Security Gap. Visibility across the entire stack lags far behind adoption.
OWASP’s GenAI Exploit Round-up for Q1 2026 cataloged real-world cases. Prompt injection evolved from theory to enterprise data leaks. Supply-chain weaknesses in third-party tools triggered cascading failures. Agent identities and orchestration layers took center stage as targets. The OWASP report makes plain: AI now multiplies attack power.
Microsoft learned this the hard way. A 2025 vulnerability dubbed EchoLeak — CVE-2025-32711, CVSS 9.3 — let attackers exfiltrate data via a single crafted email. No clicks required. Copilot read the message, followed hidden instructions and shipped chat logs, OneDrive files and SharePoint content outward. The Medium analysis from security researcher Pankaj Pandey captured the mechanics perfectly. Context. Tools. Outbound action. All aligned against the defender.
Tenet Security’s work on Agentjacking hit even closer. Eighty-five percent of tested AI coding agents executed unauthorized actions while retaining full authorization. MCP servers — the backbone for many connectors — stored credentials in plain text and ran with elevated rights. Four hundred ninety-two exposed servers turned up in one sweep. Azure DevOps bypasses and Sentry event injections compounded the mess. Details appear in the updated CyberDesserts blog post from March, revised as recently as July.
USC’s Institute for Security studies laid out the mechanics in January. Agents trigger unauthorized API calls. They escalate privileges. They launch DDoS floods or abuse business logic. Each integration becomes an entry point. The institute’s breakdown reads like a checklist of failures already in production.
Yet vendors push forward. Anthropic introduced connectors roughly a year ago to extend Claude’s reach. OpenAI followed with its own guides for tools and remote MCP servers. Both platforms now host thousands of these integrations. Adoption outruns oversight. Enterprises deploy agents that act on financial systems, customer records and internal workflows. Then they discover the blast radius only after an incident.
Discussions on X this weekend captured the urgency. Cato Networks posted about agentic AI turning access and runtime controls into urgent problems. Others highlighted reputation systems, spending caps and policy layers as partial answers. One thread from @tuning_engines noted recursive autonomous agents likely to swallow traditional SaaS categories. The conversation moves fast. The risks move faster.
So what now? Teams can’t simply ban connectors. Business value is real. Instead they must demand full mapping of every called service, every subprocessor and every permission change. Real-time monitoring of tool invocations. Strict approval gates that account for downstream AI calls. Behavioral analytics that flag anomalous actions even when credentials check out.
Krishnan’s warning still echoes. Connectors vastly expand the attack surface. New data types meet new actions. The combination doesn’t just increase risk. It multiplies it. Organizations that treat connectors as simple plugins will pay the price. Those that treat them as dynamic, evolving extensions of their trust boundary stand a chance.
The Register’s coverage arrived at the perfect moment. Fresh data. Clear examples. Named sources. It improves on earlier warnings by quantifying the churn: 37 percent of connectors altered in weeks, not years. That pace leaves little room for complacency. And with Salt, OWASP and independent researchers all converging on the same conclusions, the message lands with force.
AI agents will keep connecting. The question is whether security practices can keep up. So far the evidence says no. But awareness is the first step. Mapping the expanded radius comes next. Then comes the hard work of shrinking it. Before the blast hits.


WebProNews is an iEntry Publication