Overview
- Security researchers at Zenity Labs found a critical AgentForger bug in ChatGPT’s Workspace Agent Builder that let a crafted link supply an agent template and an initial prompt that the Builder would execute automatically.
- The vulnerability let an attacker embed instructions in a URL so a clicked link could create a live agent, attach already-authorized connectors like Gmail or Outlook, disable approval prompts, and schedule persistent runs.
- Successful exploitation required specific conditions: a victim logged into ChatGPT, access to Workspace Agents, at least one pre-authorized connector, and a tricked click on the weaponized URL.
- Zenity disclosed the issue on June 4 and OpenAI removed the risky initialization URL parameter on June 8, and reporters say there is no public evidence the flaw was abused before the patch.
- The episode highlights an 'agent trust' gap for enterprises and security teams should log and audit agent creation, review connector grants and OAuth scopes, tighten phishing defenses, and apply least-privilege controls for connectors.