2 comments

  • snlr 3 hours ago
    "Publisher" was created as a plugin for ChatGPT's web UI. It's a regular MCP server, so any client is technically supported. The basic thought is making website publishing "zero-click" by sending the data to the user's own Cloudflare account directly.

    I'm assuming that I introduced specific security issues while simplifying this workflow. Docs note that users currently have to place considerable trust in the vendor. The code itself is written almost exclusively by Astra 6.

    I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to the user that the code that is about to be installed in their CF Workers is not malicious or compromised?

    Cleaned-up notes on security are at https://github.com/JumperMCP/chatgpt-to-public-page#security... and more slop-y ones in https://github.com/JumperMCP/chatgpt-to-public-page/blob/mai...

    • soltanov 2 hours ago
      Good project idea. Publish reproducible builds with release checksums, and trust will follow.
  • Sattyamjjain 11 minutes ago
    [flagged]