The thing that's affected here is the responses you alone see.
They let anyone create and use one after all.
The only reason approval exists at all is so users aren't tricked into running low quality or spammy plugins.
You could consider this similar to someone revealing that lots of apps banned from app stores are available on other websites and one could write the headline "banned app leaks onto apkmirror.com, is google security compromised?"
Really? Allowing the suppliers of plugins to verify that ChatGPT understands the descriptions and uses them as expected (especially for ones which perform actions beyond data retrieval) before releasing them into the wild as intermediaries between users and the systems exposed by them isn’t part of that?
As an external observer, all I can say is controlling access to plug-ins via client side validation was an unusual choice and it makes me worried they made the same unusual choice elsewhere to protect data I care about.
Did I hack the site by using this unreleased feature?
This is a fairly large assumption, that the secret was important to them. Sometimes a curtain in front of the stage is all that’s needed, until things are ready.
One would reasonably consider that the secret should be important to them, given their express concern over safety considerations in particular.
The plugin system is completely open. It's a manifest file like a robot.txt. You can hook up the API to those endpoints yourself with minimal technical skill.
Many people had already integrated Wolfram and that was before there was an open format specifically designed to be easily integrated into ChatGPT.
At the end of the day for how overused the term "FUD" is on this site, this is the first time I've actually seen it in action.
Leaving aside OpenAI’s intention, its an indication of OpenAI’s failure to restrict access via their system to something to which they have represented to plugin suppliers that their system will restricted access to only a small, supplier-identified group of testers.
If you look at the list of plugins, some are non-prod versions, some are internal to other companies - eg the IAM server for Netflix’s Workforce tools.
> evil plugin
> DAN plugin
> froge
> evil status
And it looks like there's many people high up in governance that get access to OpenAI's products before the general public.
Nobody knows?