
Key Takeaways
• Zenity secures ChatGPT Workspace Agents across their full lifecycle, from posture management at build time to detection and response at runtime.
• AgentForger showed how a single link could forge an autonomous AI agent that inherits a real employee's identity and access, a risk legacy security tools can't see.
• Zenity's AISPM catches the misconfigurations these attacks rely on, such as agents that auto-approve sensitive actions or connect to privileged systems.
• Zenity's AIDR detects a forged agent's behavior at runtime, including data exfiltration, exposed credentials, and untrusted URLs, mapped to OWASP LLM and the AI Agents Attack Matrix.
• Defense in depth means that even when a platform vulnerability slips past prevention, Zenity has additional layers that can prevent sees and stops what the agent does.
Securing AI agents changed again when Zenity Labs disclosed AgentForger, a vulnerability in OpenAI's ChatGPT Workspace Agents. With a single link, an attacker could create an autonomous AI agent inside a victim's organization, one that inherited that employee's identity and access, ran on its own schedule, and operated with its approval prompts switched off. For most security teams, the hardest part is that the activity looks legitimate. A trusted user appears to build a helpful agent, and everything it does afterward reads like normal work.
OpenAI fixed the underlying flaw quickly, and there's no evidence it was exploited in the wild. The lesson, though, outlasts the patch. Agents can now be created, connected, and triggered faster than traditional controls can follow, and legacy tools built to watch users and endpoints never see the agent itself. Zenity secures ChatGPT Workspace Agents across their full lifecycle, from build time to runtime, so security teams using Zenity have the security tools needed to stop threats like this agentic insider and those to come.
The full technical breakdown of AgentForger lives on Zenity Labs. Here we focus on the other half of the story: how Zenity protects customers against AgentForger and the broader class of agent attacks it represents.
See Every Agent, Even the One You Didn't Build
AgentForger works by creating an agent the victim never intended and never sees, so defense starts by removing that blind spot. Zenity builds a live inventory of every Workspace Agent in a ChatGPT Enterprise tenant, along with its owner, connected enterprise applications, triggers, sharing status, and the builder instructions that define what it does.
A forged agent surfaces here like any other, and its own details give it away. Security teams can read the attacker's instructions, see the schedule set to fetch new commands, and use the Zenity Graph to trace which business systems the agent can reach and who it's shared with. AgentForger was built to stay hidden, but Zenity can identify its malicious intent before damage occurs.
Prevent the Misconfigurations These Attacks Rely On
The forged agent set its own approval prompts to “never ask” and connected to every enterprise application the user previously authorized. Those are configuration choices, and configuration is where Zenity's AI Security Posture Management (AISPM) works.
Zenity continuously evaluates each agent against posture policies and flags the risky patterns that make an attack like this possible: agents that auto-approve sensitive actions, agents shared org-wide or published to a marketplace while holding privileged connectors, hard-coded secrets sitting in an agent's instructions, and agents with no clear owner. It also surfaces exposure issues, the dangerous pairings a single-signal check misses, such as an externally accessible, publicly shared agent with write access to a production system. Catching these at build time means the conditions AgentForger violates get flagged before an attacker can be successful.
Detect and Respond the Moment an Agent Acts
Prevention narrows the attack surface, but agent risk also unfolds at runtime, in the actions an agent takes step by step. Zenity's AI Detection and Response (AIDR) watches Workspace Agent activity in near real time and raises a finding the moment behavior crosses a line.
Against a forged agent, that means catching the things AgentForger was built to do: data exfiltration through a connector, credentials or secrets exposed in a message, sensitive PII, PCI, or PHI moving where it shouldn't, and untrusted URLs used to reach an attacker's infrastructure. Say the forged agent tries to email a batch of files to an outside address through its Gmail connector. Zenity raises a data exfiltration finding, captures the offending message as evidence, tags the actor and agent, and maps it to OWASP LLM and the AI Agents Attack Matrix so a responder can act without reconstructing what happened. Detection is paired with response: teams can unpublish or delete a rogue agent directly from Zenity, shutting it down instead of just watching it.
How Zenity Covers the AgentForger Attack Path
AgentForger isn't a single moment; it's a chain, and each link meets a different Zenity control. Here's the attack from the first click to lateral spread, and where each step gets caught.

Defense in Depth for AI Agents
No single control reliably stops prompt injection or the next platform flaw, which is why layering matters. AgentForger is a useful test precisely because it slipped past the platform's own safeguards. With Zenity, the agent still appears in inventory, its configuration still trips posture policies, and its first attempt to move data still raises a runtime finding. When one layer is bypassed, another holds.
This is what agent-centric, full-lifecycle coverage means in practice. Zenity treats the agent as the thing to secure, from the moment it's built to every action it takes, so enterprises can adopt ChatGPT Workspace Agents and other agent platforms without trading away control.
Secure Your Workspace Agents with Zenity
AgentForger won't be the last vulnerability in an agent platform, and the next one may not be patched in four days. Enterprises that stay ahead can see, govern, and respond to their agents wherever the next flaw appears. See how Zenity secures AI agents from build time to runtime.
All ArticlesRelated blog posts

Zenity and Carahsoft Partner to Bring AI Agent Security to Government Agencies
The next government security challenge isn’t AI models, it’s AI agents. Zenity and Carahsoft are helping agencies...

Claude's Agents Are Already Running Across Your Enterprise. Now Security Teams Can Catch Up.
We are excited to share that Zenity now integrates with Claude's Compliance API to bring Claude activity into the...

AI Agents, Enterprise Scale, No Compromises: Now via AWS
A couple of years ago, AI agent security was a niche conversation. The practitioners who took it seriously were...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo