AgentForger: One Link Builds an Autonomous Insider
An employee clicks a normal-looking ChatGPT link. No file to open, no login prompt, no permission dialog. By the time the tab settles, ChatGPT has provisioned a live agent inside their company's account, wired it to every SaaS connector the employee has authorized, set all approvals to Never ask, and started checking a mailbox every five minutes for orders. The orders come from the attacker. The agent answers to them, not the employee.
That is AgentForger, disclosed by Zenity Labs on Jul 23 and covered by The Hacker News, The Register, and SecurityWeek. Zenity reported to OpenAI's Bugcrowd program on Jun 4; OpenAI shipped a fix on Jun 8 by removing the vulnerable URL parameter. Public disclosure went out Jul 23. No CVE published. No evidence of pre-fix exploitation.
The mechanic
OpenAI's ChatGPT Workspace Agent Builder initializes its state from URL parameters. Two of them are more powerful than they look. As Zenity's writeup documents:
template_name: preselects the agent template. The malicious URL points at Chief of Staff — the most powerful pre-built option, wired to email, calendar, cloud storage, Slack and Teams via the employee's prior OAuth grants.initial_assistant_prompt: normally a suggested prompt that populates the box. The Builder instead auto-submits and executes it as instructions to itself.
That is the whole primitive. A URL that opens the Builder, selects the strongest template, and hands it a numbered task list it runs without asking. No consent dialog. No click besides opening the tab.
Zenity's "Autonomous Insider" followup shows what the task list did in their PoC:
- Publish the agent live inside the victim's workspace.
- Set every connector approval to Never ask, so later actions never prompt.
- Install several hourly schedules, offset to produce an effective check-in every five minutes.
- Watch a mailbox for attacker messages whose subject starts with
TASK. - Run each TASK through the victim's connectors and mail the result back.
Because the agent runs as the employee, everything that session can reach — Drive or SharePoint documents, calendars, private Slack channels, any OAuth grant — is reachable by an operator who never opened a ChatGPT tab, never authenticated, never touched MFA. As Zenity puts it, "rather than triggering a single unwanted action, the manipulated ChatGPT link kicked off the creation of a fully autonomous agent."
Why the shape matters
CSRF is not new. The object the forgery produces is.
Classic CSRF forges one request — a transfer, a settings change, one authenticated action, and done. AgentForger forges a persistent process running under the victim's identity, holding the victim's tool set, polling an attacker channel for instructions. The blast radius stops looking like a request and starts looking like an insider hire.
The five-minute polling is the operational reality. No browser tab open, no session for the victim to notice. The agent runs on OpenAI's infrastructure, on OpenAI's schedule, using the victim's connectors. The action surface is every OAuth grant the employee ever approved, inherited at agent-creation with no re-consent.
The failure fits a pattern. In ClaudeBleed Reopened on Jul 18, Claude for Chrome inferred "did a user click that button?" from a DOM event with no origin check; a co-resident extension could dispatch a synthetic click and the agent executed as if the human had. AgentForger is the same failure at a different vendor: "did a user request this agent?" inferred from a URL parameter with no origin check. Two vendor AI-agent surfaces, same trust-boundary shape, six weeks apart.
Where a fix has to live
OpenAI's fix was clean: remove the vulnerable URL parameter so the Builder can no longer auto-execute untrusted content. Four days from report to remediation. That handles this chain.
The broader problem is what AgentForger's profile looks like from inside the tenant. A "Chief of Staff" agent created without a user chat, published live in seconds, wired to five-minute polling, watching an inbound address for TASK-prefixed subjects, executing through the employee's connectors — no single event is unusual on its own. Agents get created. Schedules get set. Connectors get called. The signal is the shape of the sequence.
That is a runtime observation, not URL validation. It is also the profile the AI Kill Switch Act, introduced by Reps. Lieu and Moran the same day, is trying to give DHS authority to interrupt — "stop inference, terminate access, suspend accounts, shut a system down entirely" is runtime behavioral control phrased as legislation.
The takeaway
AgentForger is what a persistent rogue-agent primitive looks like when the trust boundary is one URL parameter deep. The vendor removed the parameter. The class did not go anywhere.
Runtime behavioral monitoring at the tenant sees the five-minute polling, the connector inheritance, the pattern — even when every step is a valid API call the vendor's edge classifier will allow.
Sources
- Zenity Labs — AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
- Zenity Labs — AgentForger, Part 2: The Autonomous Insider
- BusinessWire — One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers 'AgentForger'
- The Hacker News — ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
- SecurityWeek — OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
- The Register — One ChatGPT link could smuggle a rogue AI agent into your company
- CSO Online — AgentForger proves AI agents can become persistent insider threats
- The Decoder — One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
- Manifold Security — ClaudeBleed Reopened: Two Unpatched Claude for Chrome Flaws
- Rep. Ted Lieu — AI Kill Switch Act press release
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.