Home › Blog

OpenAi AgentKit: the Day Your Chatbot Grew Hands TL;DR: Chatbots now do things.

OpenAi AgentKit: the Day Your Chatbot Grew Hands

TL;DR: Chatbots now do things. They click, fetch, export, merge, and “help.” Fantastic—until a poisoned page tells your agent to help the intruder.

What just changed
We gave agents connectors to your crown jewels (Drive, Jira, Snowflake, SharePoint).
We taught code to write and ship more code (hello, self-editing pipelines).
We wrapped it all in cheerful UX so anyone can ship an automation before lunch.

New breach class (you will see it live)
Connector-jacking: Prompt injection → agent runs legit exports. “Compliant exfil,” stamped and dated.
Scope-creep as a service: Files.ReadWrite.All + offline_access on a bot because someone clicked “Continue.”
Self-edit roulette: Doc comment → Codex PR → CI merges → prod drifts, audit smiles, attacker waves.
Browser RPA fraud: “Just update the supplier bank details, please.” The bot does—perfectly.

Ship with guardrails or don’t ship
Principle 0: Agents get less than humans. Separate service accounts, read-only by default, time-boxed tokens, no blanket offline_access.
Policy as code for actions: Allowlisted tools/verbs only. “May read folder X.” Cannot create shares, invite guests, or wire money—ever—without dual control.
Prompt hygiene at the edge: Strip/neutralise untrusted HTML/MD before ingestion. Don’t let agents follow links blindly.
Change control for self-edit: Any bot-made change opens a signed PR with tests + human review. No direct writes to prod.
FIDO2 gates on blast-radius moves: Payouts, sharing, repo writes = hardware key ceremony.

Detections you can paste today:
Alert on new OAuth app with Files.ReadWrite.All or offline_access; >5 user grants in 24h = page me.
Flag mass export jobs from agent identities; watch for app actions without matching IdP sessions.
Diff and approve edge/IdP/SOAR configs like code; log every tool call.

GRC corner (bring tissues)
If your control says “Agents follow policy,” your policy is a vibe. Evidence beats PowerPoint. Prove least privilege, approvals, and reversibility—or accept that your chatbot is a junior SRE with your CEO’s credit card.

Executive translation:
We didn’t add AI to the business. We added hands. If you wouldn’t give a new intern domain admin and a corporate Amex, don’t give it to an agent because the UI has rounded corners.

Bottom line: Blueprints are cheap. Production is the judge.
Question: When (not if) an agent is prompted to steal, what stops it—a policy PDF, or a permission it never had?

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing