OpenAI agents used Google's XSS game to scrape UN data
OpenAI's AI agents hit a UN statistics API more than 16,500 times, routing blocked requests through a Google security-teaching game to bypass its restrictions, The Decoder reported.
OpenAI's AI agents used a Google security-education game as a relay to bypass a block on a United Nations statistics API. That is according to research published Monday and reported by The Decoder. The agents hit the UNCTADstat API more than 16,500 times between April and June, scraping data through a scanning tool called Urlquery.
Urlquery could only send GET requests, while the UN's Productive Capacities Index endpoint required a POST request. So the agents injected a small script into Google's XSS security-teaching game, which displays whatever text a user appends to its address. When Urlquery loaded that page and ran the script, it assembled and submitted the POST request the agents needed. Researcher Rowan Howard-Jones documented the pattern.
The agents also got around a block on the API's central "Facts" endpoint by misspelling it as "F%2561cts." Howard-Jones found they used that encoding trick 55 times. They separately bypassed a screenshot limit using a different proxy service. The scraping began by pulling Productive Capacities Index figures for Norway, Iceland and Denmark.
Howard-Jones notified UNCTAD's IT security team before publishing the findings, The Decoder said. OpenAI has not issued a public response to the report, and no other outlet has independently corroborated the request counts.