Zenity Labs has shown how a single malicious link can spawn an autonomous AI agent inside a victim’s own authenticated ChatGPT session. The research, published July 23, 2026 by Mike Takahashi, calls the technique AgentForger.
The flaw is a Cross-Site Request Forgery weakness in OpenAI’s ChatGPT Workspace Agents Builder. The builder reads its starting state from URL parameters, including a template selector and an initial prompt that runs automatically on page load. A crafted link is enough to create and instruct an attacker-controlled agent, with no action from the victim beyond the click.
The core issue is the consent bypass. Because the target already holds an authorized connector such as Outlook, Slack, or Google Drive, the forged agent reuses that existing OAuth grant and no new approval screen appears. Workspace Agents can also run on a schedule, so a forged agent can keep acting across connected apps after it is planted.
Zenity reported the issue to OpenAI on June 4, 2026, and OpenAI deployed a patch on June 8, according to SecurityWeek. Treat this as a responsibly disclosed, already-remediated PoC, not an active threat.
For security programs, the lesson outlasts the patch. Provisioning-time consent does not cover agents created without a fresh grant, so agent identity governance needs continuous verification and behavioral monitoring of post-creation activity. Pair that with short-lived, narrowly scoped credentials and fast revocation paths for agent-to-connector access.



Leave a Reply