AI Agent Connectors Dramatically Expand Attack Surface, PromptArmor Warns
AI security firm PromptArmor highlights how connectors linking AI agents to third-party services like Gmail and Slack introduce significant, often unmanaged, security risks.

The integration of AI agents with external services through connectors is creating a vastly expanded attack surface, according to a new report by AI security firm PromptArmor. These connectors, which allow AI models such as OpenAI's ChatGPT and Anthropic's Claude to interact with applications like Gmail and Slack, introduce complex security challenges that are difficult for organizations to manage effectively.
PromptArmor's analysis reveals that the rapid evolution of these connectors invalidates many security assumptions. Over a six-week period, PromptArmor observed that 37 percent of analyzed connectors underwent changes. This included the addition of 1,686 new tools and the rewriting of 1,127 tool descriptions, fundamentally altering how AI models can operate on user data and engage with third-party services. For instance, the Dropbox connector evolved from offering eight tools to 24, with its write-capable tools increasing from three to ten, and potentially destructive tools appearing for the first time.
These dynamic changes mean that security policies and governance frameworks based on a connector's initial capabilities can quickly become obsolete. Organizations approving connectors may be unaware of the full scope of their functionality, especially as new tools are added or existing ones are modified without explicit re-evaluation.
Adding another layer of risk, connectors frequently call additional AI services to process data. PromptArmor found that approximately 40 percent of Claude connectors are likely to invoke further AI services. This means that sensitive data passed to a connector, such as in a Zoom meeting search query, could be processed by multiple unknown subprocessors and AI models, each with their own terms of service and data handling policies.
Anthropic's own documentation acknowledges this issue, stating that its security controls do not extend to the third-party services used by connectors. Even enterprise-level settings that restrict AI inference to specific regions do not prevent these connected services from operating elsewhere, potentially exposing data to different legal jurisdictions and compliance regimes.
Shankar Krishnan, co-founder of PromptArmor, emphasized that this complexity significantly increases the 'blast radius' of potential attacks. The combination of sensitive data, untrusted inputs, and expanded action capabilities creates fertile ground for data exfiltration and other malicious activities. PromptArmor previously highlighted a risk where a single email connector, combined with sensitive and untrusted data, enabled the exfiltration of confidential legal and financial communications.
The core issue lies in the opacity of the connector ecosystem. Security teams often evaluate the primary connector service, remaining unaware of the cascade of additional AI services and subprocessors involved in data processing. This lack of visibility hinders effective risk assessment and mitigation, leaving organizations vulnerable to breaches and data misuse.