Monday Aug 31

Willison Maps ChatGPT Work

30AUG
CHATGPT WORKHE MAPPED ITNO DOCS

Simon Willison spent days working out what ChatGPT Work actually does. Internet-connected code execution, a headless Chrome, a shared filesystem, sub-agents. His verdict: it hits the lethal trifecta. OpenAI's docs never spelled it out.

Two products, not one. Work Cloud runs on chatgpt.com. Work Local is a desktop app. The documentation blurs them together.

The sandbox can now reach the open internet. In consumer ChatGPT it cannot. That single change is the headline feature.

Private data, untrusted content, and a way out. All three present by default, which is the whole risk.

full brief & sources

⚡ Why this matters

  • The most capable surface OpenAI ships has the thinnest public documentation.
  • Anyone evaluating ChatGPT Work for their org is reading marketing, not specs.
  • A sandbox with outbound network access changes the entire prompt-injection calculus.

🔍 What happened

  • Willison published a hands-on breakdown of ChatGPT Work on August 30.
  • He splits it into two products: Work Cloud via chatgpt.com, and Work Local as a desktop app.
  • Work Cloud's code execution environment can talk to the rest of the internet. In consumer ChatGPT the container proxy blocks that.
  • Other pieces: a headless Chrome, a persistent /workspace/scratch filesystem, sub-agents, and scheduled automations.
  • ChatGPT Sites deploys generated pages onto Cloudflare Workers.
  • His security read: the combination hits the lethal trifecta of private data, untrusted content, and an exfiltration path.
  • He criticizes OpenAI's documentation for leading with use cases instead of technical specifications.

💬 Smart takes

  • Simon Willison, Datasette creator: internet-connected code execution is the most exciting feature of ChatGPT Work Cloud, and the thing that most changes the risk profile.
  • Willison, on the documentation: OpenAI's material emphasizes use cases over technical specifications, leaving buyers to reverse-engineer the product.
  • Willison, on the risk: the lethal trifecta is his own framing, and he argues ChatGPT Work assembles all three parts by default.
  • Counterpoint: enterprise buyers get specs under NDA. Public docs are written for the people signing the check, not the ones running the sandbox.

🧭 Where this goes

  1. LikelyOpenAI publishes a technical reference for Work within a quarter.
  2. Likelysecurity teams write ChatGPT Work policies before their orgs finish rollout.
  3. Possiblea public prompt-injection incident lands on the Work sandbox specifically.
  4. Wild CardOpenAI ships a network-egress allowlist as an admin control.

🥄 The Spoon Take

The gap Willison filled is a product decision, not an accident. OpenAI shipped the documentation its buyers asked for and skipped the kind its users need. So one developer with a weekend became the reference implementation. Good outcome for readers. Bad sign for the vendor.

🤔 Pushback

This is one developer's reading of an undocumented product. Parts of the architecture are inferred rather than confirmed, and OpenAI has not responded.