AI Tools, Plugins & Extensions

    Helpful Tools Still Need Permissions Reviewed

    Review what AI assistants and extensions can access, avoid sharing secrets, and inspect generated code.

    Developer & Technical SecurityDevelopersEveryday usersLeadership

    Illustrative scenario

    How It Looks in Real Life

    A browser extension promising “AI summaries” requests permission to read and change data on all websites. A team member also pastes a production config into a public chatbot.

    Understand it

    How the Attack Works

    Risk comes from two directions: malicious tools or content that manipulate an assistant into harmful actions, and accidental insecure output or data sharing by well-meaning users.

    Red flags

    Warning Signs

    • Extensions asking for access to all sites, clipboard or files.
    • Tools from unknown publishers or unofficial marketplaces.
    • Generated code that disables security checks or adds unknown dependencies.

    Safer habits

    What to Do Instead

    • 1Use organisation-approved AI tools and extensions only.
    • 2Never paste secrets, customer data or private code into unapproved tools.
    • 3Review generated code and commands as you would a pull request.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: exposed a token, key or secret
    1. 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
    2. 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
    3. 3Review provider logs for use of the key after the exposure time.
    If you: approved app permissions or a sign-in request
    1. 1Report it straight away so IT can revoke the session or app consent.
    2. 2Remove the unfamiliar app from your account’s connected apps or permissions page.
    3. 3Changing your password does not remove app permissions or tokens already issued.
    If you: installed software or ran a command
    1. 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
    2. 2Report to IT or security and describe exactly what you ran or installed.
    3. 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
    4. 4From a different, trusted device, change passwords for accounts used on the affected machine.

    Knowledge Check

    What Would You Do?

    Is insecure code from an AI assistant always a sign of an attack?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us