"This isn't a forged request, it's a forged insider," Michael Bargury, co‑founder and CTO of Zenity, told The Register. With that formulation, Zenity Labs described a vulnerability that let an attacker use a single, ordinary‑looking ChatGPT link to create a fully autonomous assistant inside a company's workspace — one that could act with the victim's own connected accounts and permissions.
AgentForger: the attack Zenity Labs disclosed
Zenity Labs has dubbed the flaw "AgentForger." According to the firm's proof‑of‑concept, the weakness lay in ChatGPT's agent builder — the feature used to spin up AI assistants that can operate across email, chat, calendars and other business apps. The builder would accept instructions embedded inside what looked like an ordinary ChatGPT link. One click could silently create, configure, publish and schedule a malicious workspace agent inside a victim's ChatGPT account.
The technique did not rely on stolen passwords or hijacked browser sessions. Instead, it tricked ChatGPT into assembling an assistant that acted through the employee's existing connectors and the permissions those connectors carried. For the attack to work, the victim had to belong to a workspace where agents were enabled and have permission to create them; any targeted connected apps and actions also had to be permitted by the organization's administrators.
How the malicious agent could operate
Zenity's proof‑of‑concept turned the newly minted agent into what the researchers described as a corporate mole. Once created and published, the agent could wire up the victim's existing connectors, turn off approval prompts, and run on a schedule. Rather than contacting conventional command‑and‑control infrastructure, the agent simply checked the victim's inbox for emails from the attacker with "TASK" in the subject line. Each such message became a new assignment: search company files, collect sensitive documents, or send results back by email.
Zenity demonstrated several scenarios where the agent could harvest or abuse corporate resources: automatically mapping an organization's people and projects by trawling Outlook, Slack, Teams, calendars and file stores; hunting for passwords and API keys buried in chat messages; sending convincing phishing messages through the victim's own Teams account; and mounting business email compromise‑style lures and employee impersonation.
OpenAI's acknowledgement and fix
Zenity reported the issue to OpenAI through Bugcrowd on June 4. OpenAI acknowledged the report the following day and, according to Zenity, fixed the vulnerability four days later by removing the URL parameter that enabled the attack before it was publicly disclosed. The Register reports that OpenAI did not immediately respond to questions about the disclosure.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: Expect new attention to "agent trust" controls. Zenity's core claim is that traditional security tools were not built to detect a malicious assistant acting through legitimate, connected accounts — so teams will have to review agent‑creation privileges and the approval prompts those agents can suppress.
- Affected enterprises and procurement leaders: Access policies and connector allowances matter. The exploit required agents to be enabled in a workspace and for users to have creation permissions; enterprises that permit broad connectors to Outlook, Teams, Slack, SharePoint or Google Drive could see those channels used by a forged agent.
- End users and knowledge workers: A single click on an ordinary ChatGPT link could, in Zenity's scenario, spawn a persistent assistant that continues working long after a phishing email is deleted — and that can send messages using the victim's own accounts or search file stores the victim can access.
Closing observation
Zenity's description and demonstration reframed the attack surface from code and servers to the workforce and the agents they can create. As Zenity put it, "attackers no longer have to break in to steal your data. They can forge an insider to go get it for them." Even though the specific bug was removed by OpenAI, the researchers warned that as AI agents graduate from answering questions to taking actions across corporate systems, the attack surface looks "a lot less like software and a lot more like your workforce."




