AI Learn
OpenAI · ChatGPT Tutorial

Install a ChatGPT plugin and connect an external app safely

Review what a plugin contains, connect only the app permissions you need, run one bounded task, and verify every external action.

Reviewed September 19, 2026Independent tutorialFeatures may vary
Not official support. AI Learn is an independent education site and is not affiliated with OpenAI. Check the provider’s current documentation for plan-specific limits, pricing and feature availability.
Before you start

The Plugins directory is the main discovery surface for reusable workflows in current ChatGPT and Codex. A plugin can contain skills, connected apps and templates; installing it does not bypass provider or workspace permissions.

1. Inspect the plugin before installing

Read the description, included apps, setup requirements, verification status if shown, and the provider privacy/terms links. Know whether it only provides instructions or can read and change external data.

2. Connect the correct account

When an included app needs authorization, sign in to the intended account and read the permission screen. Avoid granting a broad personal account when a narrower work account is the real target.

3. Start with a read-only test

Ask for a small information-retrieval task first: find one file, list one calendar event, or summarize a thread. Confirm the plugin is looking at the correct source before allowing write actions.

4. Treat external writes as transactions

For sending, creating, deleting or editing external data, inspect the proposed target and content. If approval is shown, use it as a final review point rather than clicking through automatically.

5. Review and disconnect unused access

Periodically check Plugins/Apps and your provider’s connected-app settings. Remove connections you no longer use, especially high-privilege ones.

Try this prompt

Use this connected app only to read the minimum information needed for this task. First tell me what source and account you will access. Do not send, delete, create or modify anything unless you show me the exact proposed action first.

Common mistakes

Installing by name alone without reviewing the provider; granting broader permissions than the workflow needs; testing first with a destructive action; confusing an “OpenAI Verified” badge with your own security or vendor review.

Finish check

You know exactly which app/account is connected, the first workflow works with least privilege, and any write-capable action has a human review point.

开始之前

当前 ChatGPT 和 Codex 主要通过 Plugins 目录发现可复用工作流。一个插件可能包含技能、外部应用和模板;安装插件并不会绕过外部服务或工作区本身的权限控制。

1. 安装前先看插件到底包含什么

阅读描述、包含的应用、设置要求、可能显示的验证状态,以及提供方隐私和条款链接。先弄清它只是提供指令,还是能读取甚至修改外部数据。

2. 连接正确的账号

如果插件里的应用需要授权,只登录真正要用的账号,并认真看权限页面。不要因为方便,就把权限很大的个人账号接到原本只需工作账号的流程里。

3. 先做一个只读测试

第一次先做小型信息读取:找一个文件、列一个日历事件、总结一个线程。先确认插件读的是正确来源,再考虑允许写入操作。

4. 把外部写入当作“交易”审查

发送、创建、删除或修改外部数据前,检查目标对象和内容。出现审批界面时,把它当成最终人工复核点,不要习惯性一路确认。

5. 不用的连接及时断开

定期检查 Plugins/Apps 和外部服务自己的已连接应用设置,长期不用的连接尤其是高权限连接要移除。

可以直接套用的提示词

这次只使用已连接应用读取完成任务所需的最少信息。先告诉我你准备访问哪个来源和账号;在你向我展示准确的拟执行操作之前,不要发送、删除、新建或修改任何外部内容。

常见错误

只看名字就安装,不看提供方;授权范围远大于实际任务;第一次测试就做删除或发送等破坏性操作;把“OpenAI Verified”误解为可以替代自己的安全和供应商审查。

完成检查

完成后,你应该准确知道连接了哪个应用和账号;第一个流程按最小权限工作;所有能改动外部数据的动作都有人工复核点。

開始之前

當前 ChatGPT 和 Codex 主要通過 Plugins 目錄發現可復用工作流。一個外掛可能包含技能、外部應用和模板;安裝外掛並不會繞過外部服務或工作區本身的權限控制。

1. 安裝前先看外掛到底包含甚麼

閱讀描述、包含的應用、設置要求、可能顯示的驗證狀態,以及提供方隱私和條款連結。先弄清它只是提供指令,還是能讀取甚至修改外部數據。

2. 連接正確的賬號

如果外掛里的應用需要授權,只登錄真正要用的賬號,並認真看權限頁面。不要因為方便,就把權限很大的個人賬號接到原本只需工作賬號的流程里。

3. 先做一個只讀測試

第一次先做小型資訊讀取:找一個檔案、列一個日曆事件、總結一個線程。先確認外掛讀的是正確來源,再考慮允許寫入操作。

4. 把外部寫入當作“交易”審查

發送、創建、刪除或修改外部數據前,檢查目標對象和內容。出現審批界面時,把它當成最終人工復核點,不要習慣性一路確認。

5. 不用的連接及時斷開

定期檢查 Plugins/Apps 和外部服務自己的已連接應用設置,長期不用的連接尤其是高權限連接要移除。

可以直接套用的提示詞

這次只使用已連接應用讀取完成任務所需的最少資訊。先告訴我你準備訪問哪個來源和賬號;在你向我展示準確的擬執行操作之前,不要發送、刪除、新建或修改任何外部內容。

常見錯誤

只看名字就安裝,不看提供方;授權範圍遠大於實際任務;第一次測試就做刪除或發送等破壞性操作;把“OpenAI Verified”誤解為可以替代自己的安全和供應商審查。

完成檢查

完成後,你應該準確知道連接了哪個應用和賬號;第一個流程按最小權限工作;所有能改動外部數據的動作都有人工復核點。

Official references

Check current product details at the source

Related practical tutorials

Continue with another single-task workflow.

All tutorials →