PromptArmor finds rapid security drift across AI connectors

PromptArmor says 37% of the 2,517 Claude and ChatGPT connectors it tracked changed during a six-week study, with some gaining new write actions, OAuth scopes or model instructions after deployment. The findings make connector approval a continuing monitoring problem, not a one-time review.
PromptArmor found that AI connectors can change materially after an organization first reviews them. In a six-week study spanning mid-May through the end of June 2026, the security company recorded capability, permission or configuration changes in 931 of 2,517 connectors available for Claude and ChatGPT. That is 37% of the connectors it tracked.
What changed
PromptArmor says existing connectors added 1,686 tools during the study. It also recorded 1,127 rewritten tool descriptions, 664 tools with changed inputs, 86 newly requested OAuth permission scopes and 283 connectors that began placing custom instructions into the model's context.
Some changes expanded what an agent could do. The study found 21 connectors that began as read-only but later gained tools capable of creating, editing, deleting or sending content. PromptArmor's Dropbox example grew from eight tools to 24, from three write-capable tools to 10, and from no tools marked destructive to four. These figures describe observed catalog changes, not confirmed malicious behavior or a reported breach.
The Register independently reviewed the findings and highlighted the governance problem: a connector approved on one set of capabilities may present a different risk profile weeks later. Its reporting also noted PromptArmor's concern that connectors can combine access to sensitive information, untrusted external content and actions that communicate outside the organization.
A second layer of data exposure
In a companion analysis, PromptArmor reviewed 7,517 tools across 487 Claude connectors. It classified 189 connectors, or about 39%, as highly likely to call an additional AI service for generation, search, summarization or another model-backed function. The researchers cautioned that data sent through a connector may therefore be handled under a downstream provider's residency, retention and processing terms as well as those of the connector vendor.
That result is a risk-screening finding rather than proof that every flagged tool mishandles data. It does show why teams need to understand the full processing chain behind an integration instead of treating the visible connector as the last stop.
What practitioners should take from it
For security and platform teams, the practical lesson is to treat connector approval as a versioned control. Monitoring should capture tool additions, permission-scope changes, endpoint changes and newly introduced model instructions. Connectors with write or destructive actions deserve tighter scopes and renewed review when their capabilities change.
The research also argues for evaluating connectors in combination. A read path into sensitive business data becomes more consequential when the same agent can consume untrusted material and send information through another service. The useful question is not only whether a connector was safe when enabled, but whether its current capabilities still match the access decision the organization made.
Key Points
- 1PromptArmor recorded changes in 931 of 2,517 connectors between mid-May and the end of June 2026.
- 2Existing connectors added 1,686 tools; 21 connectors that began as read-only gained actions that could create, edit, delete or send content.
- 3A companion review found 189 of 487 Claude connectors appeared likely to call another AI service, adding downstream data-processing considerations.
Scoring Rationale
The research measures fast-moving permission and capability drift across large Claude and ChatGPT connector catalogs, with direct implications for enterprise AI governance. Its practical importance is high, although the measurements come from the security vendor that conducted the study and do not describe a single confirmed breach.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

