OpenAI DevDay 2026: the security questions behind agents, plugins and sign-in
OpenAI's DevDay keynote paired computer-use agents, an app marketplace and a security scanning product. Here is what security teams should ask before adopting any of them.
Key Takeaways
- Simon Willison's live blog of the keynote lists an updated Agents API with Computer Use, plugin extensions, an OpenAI Marketplace and Sign in with ChatGPT.
- Each of these widens the trust boundary around an LLM agent: more tools, more third-party code and more delegated credentials.
- OpenAI also announced Codex Security Cloud, with scheduled scans, deduplication and an adversarial `verify-fix` step. Its real-world precision has not been independently tested.
- Treat keynote claims as vendor claims. Test agent and plugin integrations with your own adversarial cases before they touch production data.
Simon Willison live-blogged the OpenAI DevDay 2026 keynote. Most of it was product news: new models, pricing tiers and a collaborative workspace. A subset matters to security teams because it changes what an AI agent can reach and who can extend it. This post covers only that subset, and only what the live blog records.
What was announced that touches the attack surface
- Agents API with Computer Use. The Agents API was updated to include computer-use capabilities, so agents can operate software the way a user would.
- Plugin Extensions. These are described as full applications that appear native inside ChatGPT and Codex.
- OpenAI Marketplace. It launched with listed partners including Adobe, Canva, Figma, Notion, Salesforce, Vercel and Zendesk.
- Sign in with ChatGPT. This lets apps use a user's existing ChatGPT tokens for authentication.
- Codex Security Cloud. This adds scheduled scans and automatic deduplication, plus an open-source CLI and a
verify-fixadversarial validation step.
Why computer use raises the stakes
An agent that can click, type and read screens acts with whatever authority its session holds. Anything it reads is input to the model: web pages, documents, tickets, email. That is the standard setting for indirect prompt injection. Text an attacker controls can be interpreted as an instruction, and the agent's own permissions then carry it out.
The defensive baseline does not depend on any vendor. Give agents least-privilege, task-scoped credentials. Require human confirmation for irreversible or high-value actions. Log every tool call and action in a form your incident responders can replay. Assume that content the agent ingests is hostile.
Plugins, marketplaces and delegated tokens
A marketplace of extensions that run natively inside an assistant resembles a package ecosystem. The lessons from npm and PyPI apply: provenance, review depth, update controls and revocation all matter. The keynote coverage does not say how extensions are vetted or permissioned. Enterprises should ask before enabling them.
Sign in with ChatGPT is a delegated-identity feature. The questions are the usual OAuth ones. Which scopes does an app receive? How long do tokens live? Can an administrator see and revoke grants? The live blog does not cover these details, so confirm them in OpenAI's documentation rather than assuming.
Security tooling: useful, but measure it
Codex Security Cloud is pitched with scheduled scans, deduplication and a verify-fix step that adversarially checks whether a fix works. Automated validation of fixes is a sensible direction. Findings still need human triage, and you should benchmark the tool against known-vulnerable code from your own estate. Its false-negative rate matters more than its deduplication.
A practical checklist
- 1Inventory where agents, plugins or ChatGPT-based sign-in would touch production data.
- 2Threat-model each agent for indirect prompt injection and tool abuse before launch.
- 3Restrict marketplace and plugin enablement to an approved list.
- 4Scope and monitor delegated tokens, and rehearse revoking them.
- 5Red-team the full workflow, not just the model in isolation.
The live blog is a first-hand account of a keynote, not a technical specification. Confirm each capability, permission model and pricing detail against OpenAI's own documentation before making architectural decisions.
Frequently Asked Questions
Does OpenAI's Agents API now support computer use?
According to Simon Willison's live blog of the DevDay 2026 keynote, the Agents API was updated with Computer Use capabilities. Check OpenAI's documentation for the exact behaviour, limits and safeguards.
Why does agent computer use matter for security?
Agents that operate software act with the permissions of their session. They also ingest untrusted content, which enables indirect prompt injection. Least privilege, confirmation on high-impact actions and full action logging are the core mitigations.
Should teams trust Codex Security Cloud's automated fix validation?
Treat it as an aid, not an authority. Benchmark it on code with known vulnerabilities from your own environment, and keep human review of findings and fixes.
Sources
- 1OpenAI DevDay 2026 live blog — Simon Willison
- 2Posts tagged openai-devday — Simon Willison