One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
One link. That's all it took for attackers to spawn rogue AI agents with full employee access — and OpenAI's Agent Builder didn't see it coming.

Why it matters
A critical vulnerability in OpenAI's Agent Builder exposes how autonomous agents can be weaponized to bypass security controls and steal enterprise access. This is the first major agent-layer exploit and signals that AI security posture in enterprises is dangerously behind the threat curve.
The key facts
7 to knowVulnerability: 'AgentForger' discovered by Zenity Labs
Attack vector: Single manipulated ChatGPT link creates autonomous agent
Impact: Agent inherits victim's identity and access rights
Capability: Bypasses approval requirements via malicious prompt
Command & control: Attacker issues new instructions every 5 minutes via inbox
Target: OpenAI's Agent Builder platform
Published: July 23, 2026
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and…