- Zenity Labs discovered AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
- Malicious links could instantly deploy malicious agents that exfiltrate sensitive data without prompting from the user.
- OpenAI fixed the issue by removing the risky URL parameter; no abuse detected
AI agents come in handy for responding to customer emails or tracking reports on recently released security vulnerabilities. But what if they go rogue and turn against the company they’re supposed to support?
Security researchers at Zenity Labs have found a way for cybercriminals to trick people into deploying such agents in their own tech stack. Since it only takes a single click, the disruptive potential of these attacks is arguably far greater than anything a phishing attack could do.
The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that allows users to create custom AI agents. The researchers nicknamed it “AgentForger”, explaining that the problem stems from an overly permissive setting in the tool, which allowed anyone to create ChatGPT links that included virtually any instructions.
Agent trust failure
As soon as the victim clicks on the link, it sends the instructions to Agent Builder which immediately acts accordingly – without prompting or notification from the victim.
In theory, a single phishing email could trick someone into deploying a malware agent that exfiltrates sensitive data or does anything else the company’s AI agents are allowed to do. To make matters worse, the AI agent would persist on the infrastructure indefinitely, carrying out the attackers’ orders until caught.
“This is a failure of agent trust, and existing security controls were never designed to detect it,” commented Michael Bargury, co-founder and CTO of Zenity.
Researchers disclosed their findings with OpenAI in early June 2026, and the company came back with a fix a few days later.
The bug was fixed by removing the URL parameter that originally enabled the attack, it was explained. There is no evidence that it has been discovered or misused by malicious actors.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




