That's certainly an interesting question, that I don't have a direct answer to. But I'm curious about your thoughts on this:
> Do APIs need a more restrictive permissions model?
How would you make a distinction between my Python code making a request from your API endpoint, and a GPT-controlled Python program making the same request?