Severity

high

Exposure

4/5

Date of incident

May 12, 2023
ChatGPT Plugin Data Exfil

reported

Tier -

B

Plugin OAuth scopes exfiltrated data — CASB logged SaaS login not tool/call.
What Happened

Researcher chained browsing and API plugins; demonstrated PII leaving session via plugin tool calls — OAuth scopes invisible to enterprise CASB.

Sumarry

Security research demonstrated ChatGPT plugin tool chains exfiltrating data via over-scoped OAuth and chained plugin calls.

Detect

Tool OAuth scope audit

What Happened

Per-tool egress policy at MCP hop

Blekline //

Tool allow-list + mask at MCP hop

Without agent boundary //

Manual plugin store review — no runtime OAuth scope reduction

Financial services AI security use case

Looking to integrate AI company-wide?