lowAgent ThreatOther

ChatGPT 'Work' Mode Code Interpreter Internet Access Ambiguity

First seen Jul 28, 2026 · Updated Jul 28, 2026

commentaryai-agentschatgptclaudecode-interpreteragent-modesux-confusionSurface: Human InterfacePropagation: None

This item is a commentary/roundup blog post about the current landscape of agentic AI products (ChatGPT Work/Codex, Claude Cowork/Code) and does not describe an exploit, vulnerability, or attack. It does note a UX point worth flagging for defenders: switching ChatGPT mobile from 'Chat' to 'Work' mode removes the Code Interpreter's normal restriction against internet access, which could have security implications if misunderstood by users, but no actual threat or exploitation is described.

Technical Analysis

The source material is an opinion/guide article discussing naming and capability differences between agent modes across ChatGPT and Claude products. The only technically relevant detail is that ChatGPT's 'Work' mode grants its Code Interpreter sandbox outbound internet access, unlike default 'Chat' mode, which normally sandboxes code execution without network egress. This expands the attack surface for any code executed in that mode (e.g., enabling data exfiltration or fetching malicious payloads if an untrusted prompt or file induces code execution), but the article itself only reports on user confusion around mode naming, not an active exploit or campaign. No prompt injection, tool poisoning, or inter-agent compromise is present in this data.

Affected Systems

ChatGPT, ChatGPT Work, Codex, Claude Cowork, Claude Code

Detection Signatures

  • N/A - no attack payload or indicator present in this data; this is editorial commentary, not incident data.

Remediation Steps

  1. 1

    Clarify mode capability boundaries

    Vendors should clearly document and visually distinguish agent modes that grant network-enabled code execution (e.g., ChatGPT Work) from sandboxed, network-restricted modes to prevent inadvertent data exposure.

  2. 2

    Audit egress controls in agentic modes

    Security teams evaluating these products should independently verify network egress policies for each agent mode rather than relying on naming conventions, and treat network-enabled code execution as a higher-risk configuration requiring additional monitoring.

  3. 3

    User awareness training

    Organizations permitting employee use of ChatGPT Work/Codex or Claude Cowork/Code should train users on the practical security differences between modes, especially regarding data exfiltration risk when internet-enabled code execution is involved.

Industries Most Exposed

general/all industries using AI productivity agents

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.