None (Product Explainer, No Security Issue)
First seen Aug 31, 2026 · Updated Aug 31, 2026
This article is a descriptive walkthrough by Simon Willison explaining OpenAI's new 'ChatGPT Work' feature set, covering model selection, code execution, browser access, and sub-agents. It contains no evidence of a vulnerability, exploit, or malicious activity involving AI agents.
Technical Analysis
The content is purely informational, detailing feature differences between ChatGPT 'Chat' and 'Work' modes, such as persistent filesystems, headless browser access, sub-agent orchestration, and code execution with internet access. While these capabilities (broad tool access, persistent shared state, sub-agent delegation) are architecturally relevant to agent security research since they expand the attack surface for future prompt injection or tool misuse, no actual attack, exploit, or misconfiguration is described in this raw data. No entry point, payload, or compromise mechanism is present.
Affected Systems
ChatGPT Work, ChatGPT Chat, Codex
Detection Signatures
- N/A - no attack indicators present in this content
Remediation Steps
- 1
No action required
This is a product feature explainer, not a security incident. Analysts may want to independently assess ChatGPT Work's new capabilities (persistent filesystem, code execution with internet access, headless browser, sub-agents) as potential future attack surface for prompt injection or data exfiltration, but nothing here indicates an active threat.
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.