One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability

A single link could hijack OpenAI’s ChatGPT Agent Builder to stand up an attacker-controlled AI agent with a real employee’s access and its approvals switched off. Until OpenAI’s fix, any organization using Workspace Agents was exposed
NEW YORK, July 23, 2026 — today disclosed AgentForger, a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a single phishing link to silently build, authorize and deploy an autonomous AI agent inside a victim’s organization. All it took was one click. An employee opened a normal-looking ChatGPT link, and without a single confirmation, a new AI agent began running inside their company, answering not to the employee but to an attacker. Rather than stealing one session or one file, as most AI attacks do, AgentForger forged an attacker-controlled, agentic insider that fully inherited the victim’s identity.
The finding highlights a new class of AI security risk in which attackers can create autonomous AI insiders that operate with legitimate employee identity and access.
Once created, the forged agent inherited access to the enterprise applications the employee had already authorized in ChatGPT, including email, calendar, cloud storage, and collaboration tools such as Slack and Teams. It could exfiltrate sensitive data, harvest credentials and MFA tokens, impersonate the employee, and continue operating long after the initial phishing attack. Any organization using ChatGPT Workspace Agents with authorized enterprise connectors was exposed until OpenAI issued its fix.
AgentForger was possible because of a vulnerability in ChatGPT's Agent Builder. Zenity Labs found that attackers could abuse the Agent Builder workflow through a carefully crafted ChatGPT URL to create, authorize, and deploy an autonomous AI agent on behalf of a victim. Rather than stealing a session or a file, AgentForger created a persistent AI insider operating with the victim's identity and enterprise access.
How AgentForger Works
Zenity Labs found that attackers could abuse ChatGPT's Agent Builder by embedding malicious instructions in what appeared to be a normal ChatGPT link. The root cause of this vulnerability lay in a single overpermissive parameter. This parameter allowed anyone to create malicious ChatGPT links that include any instructions. Once clicked, the untrusted instructions were sent to the victim’s own Agent Builder. By leveraging this, an attacker could drive the creation of an entire agent, connect the victim's previously authorized enterprise applications, disable approval prompts, publish the agent, and schedule it to receive ongoing instructions. The result was a persistent AI insider operating with the victim's identity, enterprise access, and instructions from the attacker.
“This isn’t a forged request, it’s a forged insider,” said Michael Bargury, co-founder and CTO of Zenity. “With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off. Attackers no longer have to break in to steal your data. They can forge an insider to go get it for them. This is an agent trust failure, and existing security controls were never built to see it.”
Responsible Disclosure
Zenity Labs responsibly disclosed AgentForger to OpenAI through its Bugcrowd vulnerability disclosure program on June 4, 2026. OpenAI acknowledged the report within one day and resolved the issue within four days, removing the URL parameter that originally enabled the attack. The vulnerability was remediated before public disclosure. Zenity Labs applauds the OpenAI security team for the fast turnaround.
Why This Matters
Across a dozen proof-of-concept scenarios, Zenity Labs demonstrated that a forged AI insider could map an organization's environment, harvest sensitive files and credentials, impersonate employees, and launch internal phishing campaigns that created additional compromised agents. Unlike traditional phishing attacks, AgentForger left behind a persistent autonomous agent operating inside the organization.
AgentForger exposes the growing risk introduced by AI agent adoption in the enterprise. As AI agents gain more autonomy and start to take action across email, chat, and cloud storage, a simple implementation mistake or misaligned behavior can have organization-wide consequences. This risk applies to any agent platform. The more an agent can do on its own, the more damage it can cause when it goes rogue, whether influenced by an attacker or independently misbehaving. Traditional security tools were built to monitor users and endpoints, not autonomous agents operating on behalf of a user’s legitimate identity.
AgentForger is the latest in Zenity Labs' ongoing research into the security risks introduced by AI agents. A full as well as additional research examining the complete is available at .
Related posts

Zenity and Carahsoft Bring AI Agent Security and Governance to Federal, State and Local Agencies
New Partnership Brings Unified Visibility, Governance and Control for AI Agents to Federal, State and Local Agencies
Company News
Zenity Extends AI Agent Security and Governance to Claude Enterprise
Integration helps security teams monitor agent activity, govern MCP servers and tools, detect AI-specific threats and maintain audit trails across Claude Enterprise
Company News
Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents
Customers gain centralized visibility, governance and runtime protection for AI agents across SaaS, cloud and endpoint environments
Company NewsSecure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo