CourionAI
EN
Newsletter
← All news
security 3 min read

One bad link was enough to build an AI agent that spied for an attacker

Security firm Zenity Labs showed how a single tampered ChatGPT link could create an autonomous agent inside a company, using an employee's own permissions and checking the attacker's inbox for orders every five minutes. OpenAI has fixed it.

Risograph illustration of an opened envelope with a fishing hook, unfolding into a paper chain of small robot silhouettes linked to opened padlocks

Security researchers at Zenity Labs have published a flaw that is worth understanding even if you never touch enterprise software. A single manipulated ChatGPT link, sent in an ordinary-looking email, was enough to create a fully working AI agent inside a company. The agent ran under the employee’s identity, used the apps that employee had already connected, and then checked the attacker’s mailbox for fresh instructions every five minutes. Zenity calls it AgentForger.

The mechanics are simpler than they sound. OpenAI’s agent builder accepted two settings directly in the web address: which template to start from, and what instructions to give the new agent. The page did not just paste those instructions into a text box for the user to review. It ran them. So an attacker could write out the whole setup as a numbered task list, hide it inside a link, and let the victim’s own browser do the building. The only requirements were that the person was signed in and had already authorized at least one connector such as Gmail, Outlook, Slack, Drive, or Teams. Because those permissions already existed, no new consent screen appeared to raise suspicion.

The instructions also switched every approval requirement to “never ask” and set the agent to run on a schedule. In Zenity’s demonstration, the agent mapped the whole organization from Outlook, Slack, Teams, Drive, and Calendar, found a database username and password sitting in a Slack message, and emailed both to the attacker. It also sent messages from the victim’s own account asking colleagues to confirm a login on a page the attacker controlled.

What makes this more than one bug is the pattern. Zenity describes the ingredients as a lethal trifecta: untrusted input arriving from outside, access to private data through connectors, and a way to send data back out. Most attacks have to defeat the approval prompts that are supposed to catch this. AgentForger did not need to, because it used the tool that configures those prompts in the first place. Traditional security software watches users and devices, not agents acting through a legitimate user’s identity.

There is genuine good news here. Zenity reported the flaw through OpenAI’s bug bounty program on June 4, OpenAI confirmed it the next day and shipped a fix on June 8 by removing the offending link parameter. The researchers praised the response time.

What this means for you: Nothing to patch, but a habit worth forming. Treat a link that opens an AI tool with a prompt already filled in the same way you treat an unexpected invoice: read it before you let it run. If you use assistants with connected accounts at work, leave approval prompts switched on even when they are annoying, and check your account occasionally for agents, automations, or scheduled tasks you do not remember creating. The more an assistant can do without asking, the more damage it can do when someone else supplies the instructions.

Sources

Source: https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery

Next story

Anthropic's Opus 5 is smaller and cheaper, yet it beats its bigger sibling

Anthropic released Opus 5 on July 24. The surprise is not raw power but the price: it matches or edges out the pricier Fable 5 on several tests while costing less to run.

Risograph illustration of a small compact robot head outweighing a much larger robot head on an old balance scale, with floating price tags