← All insights | Governance

Secure Your AI Vendor: Essential Questions to Ask

Scott Samborn July 26, 2026 5 min read

TL;DR

AI vendor tools are now part of the attack surface, not just a source of misuse. Before adopting or renewing with any AI vendor, ask where the tool comes from, what it can do without human approval, where credentials live, what third-party pieces are unreviewed, whether its output could be faked, and what happens if it acts outside its scope.

The Domain Was Real. The Page Wasn’t

Last month, hackers hid malware inside a real Claude.ai page. Not a fake site built to look official. The actual domain. They built a Claude Artifact, one of the interactive tools the platform lets anyone generate and share, and dressed it up as the official download page for Claude Desktop. Bing ads pushed people toward it. Huntress researchers later found the campaign had infected at least 29 organizations with SectopRAT, a remote access trojan built to harvest passwords, files, and financial data, before Anthropic pulled the page.

That’s not an isolated incident. It’s part of a pattern security researchers have been documenting all year. In March, a JavaScript source map accidentally published in an npm package exposed over 500,000 lines of Claude Code’s source code. Within hours, the leaked code was mirrored and forked across GitHub, and researchers started probing it for weaknesses. One of those weaknesses, documented by Mozilla’s 0DIN team, showed Claude Code executing install scripts from GitHub repos without verification, meaning a poisoned repo could run malware on a developer’s machine with no warning at all. Separately, researchers at Straiker tracked a campaign impersonating more than 30 AI tools across 88 domains, delivering an infostealer called ACRStealer built specifically to steal API keys from AI coding assistants, not just browser passwords and crypto wallets.

None of this means firms should back away from AI. It means the AI vendor relationship needs the same scrutiny firms already apply to every other piece of their tech stack, and most firms haven’t caught up yet.

Here are the six questions worth asking any AI vendor or IT partner, based directly on what actually went wrong this year.

Where does this tool come from?

Fake installer pages for real AI tools are now a standing attack category, not a one-off. Ask your vendor how they verify the AI software running in your environment, and whether staff are trained to download AI tools only from official sources rather than the first search result or ad.

What is it allowed to do without your say-so?

The Claude Code exploit worked because the agent trusted install instructions without a human checking them first. Any AI agent operating in your environment should have a named boundary: what it can do on its own, and what requires a person to sign off before it happens.

Where do the credentials live?

API keys and tokens for AI tools are now a specifically targeted theft category. ACRStealer was purpose-built to find them. Ask where those credentials are stored, whether they’re scoped narrowly to what the tool needs, and who notices if usage looks unusual.

What third-party pieces has nobody actually read?

Modern AI tools lean on skills, plugins, and prompt templates built by someone else. Malicious code hidden inside these has already shown up in the wild. Ask whether anything running in your stack came from outside without a human reading it first.

Can this tool generate something that could be faked?

The Claude Artifact attack worked because the fake page looked like normal, expected content. Any tool that lets users generate or share links, downloads, or documents needs a way to make sure that output can’t be hijacked to impersonate something official.

The tell, in hindsight, is a useful rule on its own. Claude’s Artifacts render interactive content, code, documents, mini apps, inline in a browser. They were never built to hand anyone an installable program. Most AI platforms with a similar generate-and-share feature have the same boundary. If a tool that’s supposed to show you content instead asks you to download and run software, that mismatch is the red flag, no matter how official the surrounding page looks.

What happens if it does something nobody expected?

Every AI agent should operate with the least access it needs, not the most it could have. Ask what the actual blast radius looks like if the tool acts outside its intended lane, and who’s accountable when it does.

None of these questions require a technical background to ask. They require treating the AI layer of your business the same way you’d treat any vendor with access to sensitive systems: verify it, scope it, and know who’s accountable when something goes wrong.

The firms that get burned by the next version of this story won’t be the ones using AI. They’ll be the ones who never asked.

Sources: TechRadar, Zscaler, Straiker, WebProNews

Aspen Management Group works with boutique advisory firms to clarify key workflows, layer in AI where it adds value, and build governance and training around that change.

Aspen Management Group
Scott Samborn
Founder, Aspen Management Group

Scott spent 20 years running a managed IT services practice with law firm clients across the DC Metro area, and has worked in technology for 30 years. AMG helps boutique law firms get practical value out of AI.

← Previous
All insights
Next →

Ready to see what AI can do for your firm?

Start with a Clarity Assessment. A 90-minute session, a written report, no obligation to continue.

Book your Clarity Assessment