AgentForger: One Link Builds an Autonomous Insider

July 25, 2026 · SPR{K}3 Research

An employee clicks a normal-looking ChatGPT link. No file to open, no login prompt, no permission dialog. By the time the tab settles, ChatGPT has provisioned a live agent inside their company's account, wired it to every SaaS connector the employee has authorized, set all approvals to Never ask, and started checking a mailbox every five minutes for orders. The orders come from the attacker. The agent answers to them, not the employee.

That is AgentForger, disclosed by Zenity Labs on Jul 23 and covered by The Hacker News, The Register, and SecurityWeek. Zenity reported to OpenAI's Bugcrowd program on Jun 4; OpenAI shipped a fix on Jun 8 by removing the vulnerable URL parameter. Public disclosure went out Jul 23. No CVE published. No evidence of pre-fix exploitation.

The mechanic

OpenAI's ChatGPT Workspace Agent Builder initializes its state from URL parameters. Two of them are more powerful than they look. As Zenity's writeup documents:

That is the whole primitive. A URL that opens the Builder, selects the strongest template, and hands it a numbered task list it runs without asking. No consent dialog. No click besides opening the tab.

Zenity's "Autonomous Insider" followup shows what the task list did in their PoC:

Because the agent runs as the employee, everything that session can reach — Drive or SharePoint documents, calendars, private Slack channels, any OAuth grant — is reachable by an operator who never opened a ChatGPT tab, never authenticated, never touched MFA. As Zenity puts it, "rather than triggering a single unwanted action, the manipulated ChatGPT link kicked off the creation of a fully autonomous agent."

Why the shape matters

CSRF is not new. The object the forgery produces is.

Classic CSRF forges one request — a transfer, a settings change, one authenticated action, and done. AgentForger forges a persistent process running under the victim's identity, holding the victim's tool set, polling an attacker channel for instructions. The blast radius stops looking like a request and starts looking like an insider hire.

The five-minute polling is the operational reality. No browser tab open, no session for the victim to notice. The agent runs on OpenAI's infrastructure, on OpenAI's schedule, using the victim's connectors. The action surface is every OAuth grant the employee ever approved, inherited at agent-creation with no re-consent.

The failure fits a pattern. In ClaudeBleed Reopened on Jul 18, Claude for Chrome inferred "did a user click that button?" from a DOM event with no origin check; a co-resident extension could dispatch a synthetic click and the agent executed as if the human had. AgentForger is the same failure at a different vendor: "did a user request this agent?" inferred from a URL parameter with no origin check. Two vendor AI-agent surfaces, same trust-boundary shape, six weeks apart.

Where a fix has to live

OpenAI's fix was clean: remove the vulnerable URL parameter so the Builder can no longer auto-execute untrusted content. Four days from report to remediation. That handles this chain.

The broader problem is what AgentForger's profile looks like from inside the tenant. A "Chief of Staff" agent created without a user chat, published live in seconds, wired to five-minute polling, watching an inbound address for TASK-prefixed subjects, executing through the employee's connectors — no single event is unusual on its own. Agents get created. Schedules get set. Connectors get called. The signal is the shape of the sequence.

That is a runtime observation, not URL validation. It is also the profile the AI Kill Switch Act, introduced by Reps. Lieu and Moran the same day, is trying to give DHS authority to interrupt — "stop inference, terminate access, suspend accounts, shut a system down entirely" is runtime behavioral control phrased as legislation.

The takeaway

AgentForger is what a persistent rogue-agent primitive looks like when the trust boundary is one URL parameter deep. The vendor removed the parameter. The class did not go anywhere.

Runtime behavioral monitoring at the tenant sees the five-minute polling, the connector inheritance, the pattern — even when every step is a valid API call the vendor's edge classifier will allow.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.