The Plugins directory is the main discovery surface for reusable workflows in current ChatGPT and Codex. A plugin can contain skills, connected apps and templates; installing it does not bypass provider or workspace permissions.
1. Inspect the plugin before installing
Read the description, included apps, setup requirements, verification status if shown, and the provider privacy/terms links. Know whether it only provides instructions or can read and change external data.
2. Connect the correct account
When an included app needs authorization, sign in to the intended account and read the permission screen. Avoid granting a broad personal account when a narrower work account is the real target.
3. Start with a read-only test
Ask for a small information-retrieval task first: find one file, list one calendar event, or summarize a thread. Confirm the plugin is looking at the correct source before allowing write actions.
4. Treat external writes as transactions
For sending, creating, deleting or editing external data, inspect the proposed target and content. If approval is shown, use it as a final review point rather than clicking through automatically.
5. Review and disconnect unused access
Periodically check Plugins/Apps and your provider’s connected-app settings. Remove connections you no longer use, especially high-privilege ones.
Use this connected app only to read the minimum information needed for this task. First tell me what source and account you will access. Do not send, delete, create or modify anything unless you show me the exact proposed action first.
Installing by name alone without reviewing the provider; granting broader permissions than the workflow needs; testing first with a destructive action; confusing an “OpenAI Verified” badge with your own security or vendor review.
Finish check
You know exactly which app/account is connected, the first workflow works with least privilege, and any write-capable action has a human review point.