2026-10-11 18:04 UTC

Independent reproduction and vendor response will determine whether a crafted ChatGPT link can activate or introduce a persistent rogue agent inside an enterprise environment without meaningful user authorization.

state: resolvedheat: lowuncertainty: mediumnovelscott: noneprompt-injection agent-security enterprise-aiOpenAIChatGPT

What is this?

The case concerns a Zenity Labs disclosure dubbed “AgentForger,” described in the supplied evidence title as a CSRF-style flaw in which an attacker-controlled ChatGPT URL could allegedly forge an autonomous agent in an enterprise environment. The claimed impact is persistent agent creation or activation without meaningful user authorization, implicating OpenAI’s ChatGPT agent controls. However, the provided search snippets do not independently document the exploit, a successful reproduction, affected configurations, or an OpenAI response; they establish only broader concerns around prompt injection, excessive agency, OAuth permissions, and rogue-agent deployments.

Why it matters to Scott

No intersection found in Scott’s wikis or the radar’s accumulated pages. Although the alleged exploit concerns agent security and enterprise AI, the supplied hits do not establish that it bears on a position, project, or tracked development of Scott’s.
queries asked of Scott's wikis
  • agent creation authorization and consent boundaries
  • CSRF defenses for AI agent configuration
  • persistent prompt injection in enterprise agents
  • capability grants and least privilege for autonomous agents
  • untrusted links as agent installation vectors
  • agent provenance auditing and kill switches

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnOne ChatGPT link could smuggle a rogue AI agent into your companyBender10
🟧 echo.blog ⭐Zenity Labs’ primary technical disclosure calls AgentForger a CSRF that “forges an entire autonomous agent” via attacker-controlled URL paraZenity Labs——

Interpretation history

Decision trace