Opening SecureFlowAgentFlayer: ChatGPT Connectors Zero-Click Data Exfiltration
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zenity Labs aidefend-sf0019

AgentFlayer: ChatGPT Connectors Zero-Click Data Exfiltration

  • Autonomous Agents
  • Tool Integrations & MCP
  • Data Exfiltration
  • Credential & Identity Theft

Zenity demonstrated that a benign-looking document containing a one-pixel white indirect prompt injection could redirect ChatGPT from summarization into its connected Google Drive, use file_search to retrieve API keys, and place the keys in a Markdown image URL. ChatGPT's client-side url_safe check blocked the researchers' initial Beeceptor endpoint, but an Azure Blob image URL was trusted and rendered automatically. The resulting client request carried the keys in its query string, and Azure Log Analytics recorded them. After the victim uploaded the document, the demonstrated chain required no further clicks.

Mapped threat techniques

Source