Dashboard / Courses / Connectors, Plugins and Skills / What to Check Before You Trust One

What to Check Before You Trust One

Not every connector is equal, and anyone can build one. Before you connect something, run through five questions.

Who made it? A connector published by the app’s own company is a different proposition from one from an unknown developer. Prefer the official one, and be wary of look-alikes with a similar name.

What does it ask for? Compare the permissions to the job. A tool that summarizes your documents does not need permission to delete them. If it asks for more than it needs, skip it.

What data leaves? Anything the assistant reads through a connector may be sent to the AI company as part of the request. Do not connect a folder of sensitive client files unless you are comfortable with that.

Can it change things? Tools that can send, post or delete deserve extra caution and a human check before they act.

What could it be tricked into? Content inside a connected tool, such as an email or web page, can contain hidden instructions aimed at the assistant. That is called prompt injection, and the safety course on this site covers it in detail. For now, the practical habit is to connect fewer things and keep the powerful ones read-only.

Takeaway: connect fewer things, prefer official ones, give the least access that does the job, and stay in the loop for anything that can send or delete.

Tools, prices and features in this area change quickly. Last reviewed September 2026.