GPTs, Apps, Plugins, and Connected Workflows By the end of this lesson, students should be able to: Third-party capabilities deserve the same caution as browser extensions and SaaS integrations. Begin with the publisher: Is the identity clear? Is there current documentation? Does the requested access match the advertised function? Then inspect permissions: read, write, send, create, modify, or delete. Test with synthetic or low-risk data. Ask the GPT or plugin to state what sources and tools it used. Examine whether it follows your request, invents access it does not have, or asks for information beyond necessity. Connected content may contain malicious or misleading instructions; treat external text as data, not authority. Red flags include unexplained broad permissions, pressure to paste secrets, claims of guaranteed outcomes, hidden action steps, unverifiable citations, and refusal to explain what data is accessed. Disconnect capabilities no longer in use and periodically review active connections. Enroll to continue this lesson. The preview above shows the lesson objectives and opening lesson content. Enroll to view the full lesson, complete the practice work, and take the lesson quiz.
Lesson 2: Evaluating and Using Third-Party GPTs and Plugins
Lesson Objectives
Lesson Content
