"Publisher" was created as a plugin for ChatGPT's web UI. It's a regular MCP server, so any client is technically supported. The basic thought is making website publishing "zero-click" by sending the data to the user's own Cloudflare account directly.
I'm assuming that I introduced specific security issues while simplifying this workflow. Docs note that users currently have to place considerable trust in the vendor. The code itself is written almost exclusively by Astra 6.
I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to the user that the code that is about to be installed in their CF Workers is not malicious or compromised?
I'm assuming that I introduced specific security issues while simplifying this workflow. Docs note that users currently have to place considerable trust in the vendor. The code itself is written almost exclusively by Astra 6.
I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to the user that the code that is about to be installed in their CF Workers is not malicious or compromised?
Cleaned-up notes on security are at https://github.com/JumperMCP/chatgpt-to-public-page#security... and more slop-y ones in https://github.com/JumperMCP/chatgpt-to-public-page/blob/mai...