← Back to feed
AI SecurityEmerging1 sourceJul 6, 2023 · 23:30via Embrace The Red (AI agent security)

OpenAI Removes the "Chat with Code" Plugin From Store

Brief

In the previous post we discussed the risks of OAuth enabled plugins being commonly vulnerable to Cross Plugin Request Forgery and how OpenAI is seemingly not enforcing new plugin store policies. As an example we explored how the “Chat with Code” plugin is vulnerable.

Recently, a post on Reddit titled “This is scary! Posting stuff by itself” shows how a conversation with ChatGPT, out of the blue (and what appears to be by accident) created a Github Issue! In the comments it is highlighted that the Link Reader and Chat With Code plugins were enabled when ChatGPT created this Github Issue here .

Read more on Embrace The Red (AI agent security)