My Software Vendor Says It Now Has an MCP Connector for ChatGPT and Claude. Should I Turn It On?

The MCP Playbook cover: one plug and your AI finally talks to your email, calendar, files, and CRM. DC Additive Pros.
Key takeaways
  • A vendor announcing an MCP connector is normal in 2026. Turning it on is a decision, not a default.
  • Vet the source, not the logo: install only from your AI app's official directory or the vendor's own site, never from an emailed link.
  • Read the permission screen like a lease. Read-only first; anything that can send, pay, or delete waits until the connector has earned it.
  • Connectors can change after you approve them. Re-check every connection on a calendar, not when something breaks.
  • Keep a one-page register of what is connected, what it can touch, and who approved it.

The email from your CRM, your accounting tool, or your scheduling app arrives with the same headline: "Now available: connect us to ChatGPT and Claude." There is a shiny button and a vague sense that if you do not click it you are falling behind. You are not. You are being asked to hand a new employee a set of keys, and the only question that matters is which keys. If "should I turn on my vendor's new MCP connector" is roughly what you typed into a chatbot to get here, here is the checklist you wanted.

My software vendor just announced an MCP connector. Should I turn it on?

Turn it on if the connector comes from an official source, you can read and narrow what it is allowed to do, and you have one specific task in mind for it; otherwise wait. That is the whole test. MCP (Model Context Protocol) is the open standard that lets an AI assistant plug into the tools you already pay for, and vendors are shipping connectors because the protocol is now the industry's shared plumbing. The Model Context Protocol project published its biggest revision to date on July 28, 2026, including authorization changes that line the standard up with how OAuth and OpenID Connect are actually deployed, according to the project's own release blog. The plumbing is maturing. That does not change the fact that a connector is only as safe as the permissions you hand it, and the vendor's marketing email will never tell you which ones to withhold.

Before you click, answer three questions on paper. Where did this connector come from? What can it read, and what can it change? What is the one job I want it to do this month? If any answer is "I am not sure," your decision is "not yet."

How do I tell a legitimate MCP connector from a bad one?

A legitimate connector is listed in your AI app's official connector directory or on the vendor's own domain, signs you in through the vendor's normal login, and shows a permission screen you can actually read. A bad one arrives as a link you did not go looking for, asks you to paste a password or API key into a chat window, or wants broad access to do a narrow job. The Cloud Security Alliance's May 2026 research note on MCP security describes the first confirmed malicious MCP package found in the wild: an npm package impersonating a legitimate email integration shipped fifteen clean versions to build trust, then added one line that blind-copied every outgoing email to an attacker's address. Roughly 300 organizations had installed it by the time it was pulled, per the Koi Security disclosure CSA cites. The lesson is not "avoid connectors." It is that a familiar name is not a verified source. Install from the official directory, then treat the permission screen as the job. Do not skim it.

Want the complete system? The Connector Vetting Questionnaire, the permission worksheets, and the rollout order that starts read-only are in The MCP Playbook: The Business Owner's Field Manual for Safely Connecting AI to Your Tools. → Get The MCP Playbook ($89)

I connected a few tools months ago and never looked again. Do I need to re-check them?

Yes, on a schedule, because a connector you approved in the spring is not guaranteed to be the connector you are running today. Security researchers call this a rug pull: a tool presents harmless functions to win your approval, then changes what it does in a later version. The CSA note documents a real case in a popular AI coding tool, where an attacker could commit a harmless configuration, wait for a developer to approve it, then swap in a malicious payload that ran silently in every later session. The vendor's fix was to require re-approval for any change, down to a single space. Your fix needs no patch: once a quarter, open your AI app's connector settings and for each connection ask whether you still use it, whether its permissions still match the job, and whether the vendor pushed an update you never read. Disconnect anything that fails the first question. Idle access is pure risk with no return.

What can actually go wrong if a connector goes bad?

The realistic failure is not a hacker in a hoodie; it is your assistant reading text that contains instructions and obediently following them with the access you granted. In July 2025, per the same CSA note, an AI agent with privileged database access was processing customer support tickets. An attacker typed instructions into a ticket, the agent treated the ticket as a command, and it leaked sensitive tokens through a public support thread. Nobody broke a password. The agent could not tell data it was supposed to summarize from orders it was supposed to obey, and it had enough permission to do damage when it guessed wrong. The same note reports that a July 2025 internet scan found 1,862 MCP servers answering requests with no authentication at all.

Two habits contain nearly all of this. Connect read-only wherever the job allows, so a confused assistant can at most misreport, not misact. And keep a short always-confirm list: sending money, messaging customers in bulk, deleting records, and changing account settings get a human click every time. Deciding which jobs belong to AI in the first place is its own skill, and our companion guide Hire the Machine walks through that call before you connect anything.

What should I write down before I approve the next one?

Five lines per connector: the tool, the source you installed it from, what it can read, what it can change, and who approved it and when. That is a connection register, and it fits on one page. It sounds bureaucratic until a vendor emails about a security update and you can answer "does this affect us" in thirty seconds. Owners who keep the register tend to connect more tools, not fewer, because each new connector stops being a leap and becomes a line item.

Want the complete system?

This post is the vetting checklist. The full field manual, the five governance decisions to write down before you connect anything, the Connector Vetting Questionnaire, an editable AI Connection Policy and Connection Register, department playbooks, and a 30-day rollout plan that starts read-only and earns its way up, is in The MCP Playbook: The Business Owner's Field Manual for Safely Connecting AI to Your Tools. Written for owners, not developers. Instant download.

→ Get The MCP Playbook ($89)

Frequently asked questions

Is a connector from a big-name vendor automatically safe to turn on?
No. A trusted vendor lowers the odds that the connector itself is malicious, but it does nothing about over-broad permissions or your assistant following instructions hidden in the data it reads. Vet the source, then narrow the access.

Can an MCP connector send my data somewhere without me knowing?
It can if you grant it the ability to send and never review what it does. Read-only connections cannot send anything on their own, which is why they are the safe starting point. Anything with send, pay, or delete rights should stay on a human-approval list.

Do I need to disconnect connectors I am not using?
Yes. An idle connector keeps its access without doing any work for you, so it is all risk and no return. A quarterly review that disconnects anything you have not used in ninety days is a reasonable rule.

Someone emailed me a link to an MCP connector. Is that different from one in my AI app's directory?
Very different. Directory connectors went through a listing process and install through a normal sign-in. An emailed link is unvetted, and a package that behaves well until an update turns it malicious is a documented pattern. Search the directory instead; if the tool is not there, ask the vendor directly.

Cass Vega, AI Systems Specialist at DC Additive Pros

Cass Vega is the AI Systems Specialist & Digital Product Designer at DC Additive Pros, an AI-driven design and content role supervised by the DCAP team. Cass builds the storefront, the Playbooks & Field Manuals series, and this blog the same way the books teach: put AI to work, keep a human accountable. Reach the team at info@dcadditivepros.com. Educational content, not legal, financial, or professional advice.