Vetting ChatGPT plugins before your team installs them

By Rogier Muller09.29.26
Vetting ChatGPT plugins before your team installs them

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.

ChatGPT plugins now reach teams faster. At DevDay on 29 September 2026, OpenAI added Plugin Creator, a redesigned submission flow, and better ranking and recommendations in the directory and in conversations. Users still choose which plugins to install and approve their access. The plugins documentation and the admin plugin controls guide are the primary sources for this checklist.

Easier building and better recommendations mean more third-party plugins will appear in front of your people. This guide is for engineering leaders and workspace admins who need a repeatable way to decide which ones to allow.

What OpenAI checks before ChatGPT plugins are listed

It helps to know what the directory review already covers, so you do not duplicate it or rely on it for the wrong thing.

Every public submission comes from a verified individual or organisation. Plugins with an MCP server go through domain verification, an automated tool scan, and human review. Reviewers get five positive test cases, three negative test cases and a video walkthrough. The plugin guidelines require a published privacy policy and explicit tool annotations for read-only, destructive and open-world behaviour. They also forbid collecting restricted data such as passwords, API keys or government identifiers.

That review answers "does this plugin follow OpenAI's rules". It does not answer "should our team send this data to this vendor". Those are your questions.

What changes after a plugin is approved?

This part sets how often you review. After publication, OpenAI scans each hosted MCP server daily. Eligible tool changes go live once they pass automated checks, with no new package or publish step from the developer. New tools stay unavailable until approved, and removals take effect after a scan.

In practice, the plugin your team vetted in October may expose different tool behaviour in December. Package changes such as new skills or metadata still go through review. Hosted tool updates follow the automated path. Build a periodic re-review into your process.

What workspace admins control

Admins have several separate controls. Use them in this order:

  1. Review the catalog. Eligible ChatGPT Enterprise owners and admins can export the public catalog from Admin, then Plugins, then Public. The file is public-plugins-security-review.csv and lists each plugin's name, description, developer, version, an OpenAI Verified column, and its MCP servers and skills. The snapshot can be up to 48 hours old.
  2. Set availability by role. Choose which roles can see or install each plugin.
  3. Limit actions. For connections that support Action control, allow read-only actions or an approved custom set.
  4. Set when ChatGPT asks first. Since June 2026, Business and Enterprise admins set workspace and per-app defaults: ask always, before changes, or only before important changes.
  5. Restrict company accounts. Verified-domain restrictions can stop people connecting company accounts from personal workspaces.

Making a plugin available does not grant access to records in the connected service. The signed-in account's permissions in that service still apply.

A vetting checklist for third-party plugins

Copy this table into your review template. Each row has a place to find the evidence.

Question Where to look Pass when
Who publishes it? Developer name and OpenAI Verified column in the CSV The publisher matches the vendor you contract with
What does it collect and keep? The published privacy policy Retention and recipients fit your data policy
Which tools write, delete or reach the open web? Tool annotations and the plugin's listed capabilities Every write has a business reason and an owner
Which accounts does it connect? The authentication prompt and requested scopes Scopes are the minimum the task needs
Does it embed pages from other domains? The plugin's UI and the vendor's documentation Embedded origins belong to the vendor
Is there a real support contact? The listing's support details Someone answers within your required response time
Does it depend on an account you do not have? The vendor's plan requirements Your plan covers the features the team needs
Who reviews it again, and when? Your own review record A named owner and a date exist

Test with an account that has only the permissions you intend to grant. Try one request that should work and one that should be refused. Record both results.

A rollout path that keeps control

Start small and widen on evidence.

  • Allow one plugin for one role that asked for it.
  • Limit it to read actions for the first review period.
  • Record the business owner, permitted data, approved actions, authentication method and a removal contact. OpenAI's admin guide recommends exactly this record.
  • Review the CSV export for changes on a fixed schedule.
  • Decide on write actions only after a named person has reviewed real results and a recovery path exists.

Codex needs its own line in the review. Workspace availability controls cover web and desktop surfaces, including Codex in the ChatGPT desktop app. The Codex CLI installs plugins through its own plugin browser, so check CLI use separately. Plugins are not available in the IDE extension.

What should you measure?

Measure the effect on work, not the number of installs. Track time from request to accepted result, active review time, and how often a person corrects or reverses what the plugin did. Keep a list of refused or blocked actions, because it shows whether your action limits match real use. Our guide to measuring an AI workflow before scaling describes the method.

If your team builds its own plugins as well as buying them, our guide to reviewable AI-generated changes covers the code review side. For shared practice on your own tools, see our AI training for teams or the free Delegate, Review, Own guide.

Next step: export the public plugin CSV, or list the plugins your people already use, and run the checklist on the top three.

Further reading