Research · curated 19 Jul 2026

Connecting AI agents to outside services explodes the risk radius

Coverage timeline

discovered promptarmor.com primary 19 Jul 2026theregister.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Connector churn means security assumptions and governance approvals based on a connector's declared capabilities can silently become invalid, expanding the 'lethal trifecta' attack surface and enabling data exfiltration through third-party AI services without the defender's knowledge.

The Register reports on PromptArmor research finding that AI agent connectors — OpenAI/ChatGPT and Anthropic/Claude MCP-based integrations with services like Gmail, Slack, and Dropbox — change constantly, with 931 of 2,517 connectors (37%) changing over six weeks, 1,686 new tools added and 1,127 tool descriptions rewritten. The study found connectors gaining write and destructive capabilities (Dropbox went from 8 to 24 tools, 0 to 4 destructive), permission scopes shifting, injected model instructions appearing, and about 2 in 5 Claude connectors likely calling additional external AI services.