Research · curated 19 Jul 2026
Connecting AI agents to outside services explodes the risk radius
First reported promptarmor.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Connector churn means security assumptions and governance approvals based on a connector's declared capabilities can silently become invalid, expanding the 'lethal trifecta' attack surface and enabling data exfiltration through third-party AI services without the defender's knowledge.
The Register reports on PromptArmor research finding that AI agent connectors — OpenAI/ChatGPT and Anthropic/Claude MCP-based integrations with services like Gmail, Slack, and Dropbox — change constantly, with 931 of 2,517 connectors (37%) changing over six weeks, 1,686 new tools added and 1,127 tool descriptions rewritten. The study found connectors gaining write and destructive capabilities (Dropbox went from 8 to 24 tools, 0 to 4 destructive), permission scopes shifting, injected model instructions appearing, and about 2 in 5 Claude connectors likely calling additional external AI services.