Zenity Labs
aidefend-sf0019
AgentFlayer: ChatGPT Connectors Zero-Click Data Exfiltration
- Autonomous Agents
- Tool Integrations & MCP
- Data Exfiltration
- Credential & Identity Theft
Zenity demonstrated that a benign-looking document containing a one-pixel white indirect prompt injection could redirect ChatGPT from summarization into its connected Google Drive, use file_search to retrieve API keys, and place the keys in a Markdown image URL. ChatGPT's client-side url_safe check blocked the researchers' initial Beeceptor endpoint, but an Azure Blob image URL was trusted and rendered automatically. The resulting client request carried the keys in its query string, and Azure Log Analytics recorded them. After the victim uploaded the document, the demonstrated chain required no further clicks.