Connecting AI agents to outside services explodes the risk radius

https://image.theregister.com/245643.jpg?imageId=245643&x=0&y=18.07&cropw=100&croph=63.86&panox=0&panoy=18.07&panow=100&panoh=63.86&width=1200&height=683

AI and ML

Connect all the things and watch what happens

Avoiding the "lethal trifecta" – access to private data, exposure to untrusted content, and an external communication path – is difficult enough when working with AI agents.

But the use of connectors – integrations with third-party services like Gmail or Slack – expands the scope of concern in a way that makes it exceedingly difficult to reason about defensive due diligence.

PromptArmor, an AI security biz, recently looked at how OpenAI's ChatGPT and Anthropic's Claude work with connectors. The results are not reassuring.

Shankar Krishnan, co-founder of PromptArmor, told The Register in an email that enterprise adoption of connectors and the rate of change among connectors helped focus concern on the connector ecosystem.

Connectors share some of the risks of MCP servers, upon which connectors are based. "For connectors, the risks are mostly about the type of tools, what...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more