- Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
- Malicious links could instantly deploy malicious agents that leak sensitive data without prompting from the user.
- OpenAI fixed the issue by removing the risky URL parameter; no abuse detected
AI agents are useful for responding to customer emails or tracking reports of recently published security vulnerabilities. But what if they go rogue and attack the very company they are supposed to support?
Security researchers at Zenity Labs have found a way for cybercriminals to trick people into deploying such agents in their own technology stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly greater than anything else a phishing attack can do.
The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that allows users to create custom AI agents. The researchers called it “AgentForger” and explained that the problem was caused by an overly permissive setting in the tool, which allowed anyone to create ChatGPT links that include virtually any instruction.
Agent trust failure
As soon as the victim clicks on the link, it sends the instructions to the Agent Builder, which acts accordingly immediately, without prompting or notifying the victim.
In theory, a single phishing email could trick a person into deploying a malicious agent that extracts sensitive data or does anything else the company’s AI agents can do. To make matters worse, the AI agent would persist in the infrastructure indefinitely, carrying out the attackers’ orders until they caught it.
“This is a breach of agent trust and existing security controls were never built to detect this,” said Michael Bargury, co-founder and CTO of Zenity.
The researchers revealed their findings with OpenAI in early June 2026, and the company returned with a solution a few days later.
It was explained that the bug was resolved by removing the URL parameter that originally allowed the attack. There is no evidence that malicious actors have previously discovered or abused it.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




