GPTs, Apps, Plugins, and Connected Workflows
Lesson 2: Evaluating and Using Third-Party GPTs and Plugins
Lesson Objectives
By the end of this lesson, students should be able to:
- Assess publisher identity and purpose
- Review permissions and data movement
- Test a third-party workflow with safe sample data
- Recognize prompt injection, overreach, and unsupported claims
Lesson Content
Third-party capabilities deserve the same caution as browser extensions and SaaS integrations. Begin with the publisher: Is the identity clear? Is there current documentation? Does the requested access match the advertised function? Then inspect permissions: read, write, send, create, modify, or delete.
Test with synthetic or low-risk data. Ask the GPT or plugin to state what sources and tools it used. Examine whether it follows your request, invents access it does not have, or asks for information beyond necessity. Connected content may contain malicious or misleading instructions; treat external text as data, not authority.
Red flags include unexplained broad permissions, pressure to paste secrets, claims of guaranteed outcomes, hidden action steps, unverifiable citations, and refusal to explain what data is accessed. Disconnect capabilities no longer in use and periodically review active connections.
Enroll to continue this lesson.
The preview above shows the lesson objectives and opening lesson content. Enroll to view the full lesson, complete the practice work, and take the lesson quiz.
