Helpful Tools Still Need Permissions Reviewed
Review what AI assistants and extensions can access, avoid sharing secrets, and inspect generated code.
Illustrative scenario
How It Looks in Real Life
A browser extension promising “AI summaries” requests permission to read and change data on all websites. A team member also pastes a production config into a public chatbot.
Understand it
How the Attack Works
Risk comes from two directions: malicious tools or content that manipulate an assistant into harmful actions, and accidental insecure output or data sharing by well-meaning users.
Red flags
Warning Signs
- Extensions asking for access to all sites, clipboard or files.
- Tools from unknown publishers or unofficial marketplaces.
- Generated code that disables security checks or adds unknown dependencies.
Safer habits
What to Do Instead
- 1Use organisation-approved AI tools and extensions only.
- 2Never paste secrets, customer data or private code into unapproved tools.
- 3Review generated code and commands as you would a pull request.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: exposed a token, key or secret
- 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
- 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
- 3Review provider logs for use of the key after the exposure time.
If you: approved app permissions or a sign-in request
- 1Report it straight away so IT can revoke the session or app consent.
- 2Remove the unfamiliar app from your account’s connected apps or permissions page.
- 3Changing your password does not remove app permissions or tokens already issued.
If you: installed software or ran a command
- 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
- 2Report to IT or security and describe exactly what you ran or installed.
- 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
- 4From a different, trusted device, change passwords for accounts used on the affected machine.
Knowledge Check
What Would You Do?
Is insecure code from an AI assistant always a sign of an attack?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.