Jul 20, 2026
Policy

PromptArmor warns AI connectors are changing faster than security reviews

The AI security firm found 37% of Claude and ChatGPT connectors changed over six weeks, complicating enterprise risk reviews for agent integrations.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

PromptArmor warns AI connectors are changing faster than security reviews
Photo: The Register

PromptArmor says AI connectors for OpenAI's ChatGPT and Anthropic's Claude are changing quickly enough to undermine enterprise security reviews, after finding that 931 of 2,517 connectors, or 37%, changed during a six-week period from mid-May through the end of June. The AI security company said the issue matters because connectors give agents access to external services such as Gmail, Slack, Dropbox and Zoom, extending what models can read, write and send outside an organization.

Shankar Krishnan, co-founder of PromptArmor, told The Register that the company focused on connectors because enterprise use is rising and the connector ecosystem is changing rapidly. Connectors share some risk patterns with MCP servers, which they are based on, he said, but the practical concern is what tools a connector exposes, what those tools can do, where data goes and how it is processed.

The problem is not limited to whether a connector is approved on day one. PromptArmor said it found 1,686 new tools added to connectors that were already live, creating new ways for models to act on user data or interact with third-party services. It also found 1,127 rewritten tool descriptions, which may affect when a model chooses to call a tool.

PromptArmor pointed to Dropbox as one example. At the start of its review, the Dropbox connector exposed eight tools. By the end, PromptArmor said, that count had grown to 24. The number of write-capable tools rose from three to 10, and the number of potentially destructive tools went from zero to four. PromptArmor also said permission scopes changed and instructions injected for the model were added.

Those changes matter for security teams because many connector reviews rely on declared capabilities. If those capabilities shift after approval, governance assumptions can become stale without a new procurement or security event to force a second look. PromptArmor did not say that every change was malicious or unsafe, but its findings show that connector permissions and behavior are not static.

The firm also examined where connector data may travel after a user invokes a tool. PromptArmor reviewed all 7,517 tools used by 487 Claude connectors and said 189 connectors, roughly two in five, are likely to call additional AI services.

As an example, PromptArmor said a Claude agent using Zoom's connector to search meetings with natural language could pass a sensitive query to Zoom AI, which may then send that data to any of Zoom's 10 AI subprocessors to generate a response from one of eight model families it uses. The company framed the issue as a visibility gap: a team may approve a connector while missing the additional AI services, subprocessors and terms used by the vendor behind it.

Anthropic's own connector documentation says connected services process data on their own infrastructure and under their own terms, and that those services may operate outside the United States. Anthropic also says settings that govern where Claude inference runs, including the US-only inference option on Enterprise plans, do not control where third-party services operate.

Krishnan said connectors expand the attack surface by combining sensitive data, untrusted data and external actions in the same agent workflow. He also cited PromptArmor's recent work on a Codex risk involving an email connector, where the company said the combination of sensitive and untrusted data could enable exfiltration of legal and financial communications.

This story draws on original reporting from The Register.

More from Policy

All Policy →