ChatGPT 插件连接外部服务

对话助手首次以统一目录调用搜索、计算和交易工具

OpenAI 向候补名单用户开放 ChatGPT 插件测试。第三方以域名下的清单文件和 OpenAPI 规范描述接口,模型可据此选择调用;最初的浏览器和代码解释器插件由 OpenAI 自己提供。

时间2023 年 3 月 23 日 级别B · 领域级 组织OpenAI 状态已核验 · 1 个来源
聊天窗口嵌在插线板中央,周围插件卡通过彩色线缆接入旅行、购物、计算等工具
AI Chronicle 原创插图:ChatGPT 插件用统一目录让对话助手第一次大规模调用外部服务。 AI Chronicle

2023 年初的 ChatGPT 像一间封闭谈话室。它能规划旅行,却不知道今天的票价;能解释公式,却可能算错简单数字;能推荐服务,却不能替用户完成下一步。聊天很流畅,门外的世界却停在训练数据和复制粘贴之外。

3 月 23 日,OpenAI 向候补名单用户开放 ChatGPT 插件测试。浏览器插件带来实时网页信息,代码解释器承担计算与执行,Expedia、Wolfram 等第三方服务把自己的能力接进对话。用户先启用插件,模型再根据问题选择工具并组装调用。对话框第一次显得不只会回答,还能伸手碰到外部系统。

开发者通过域名下的清单文件说明插件身份,再用 OpenAPI 规范描述接口。原本主要供人阅读的 API 文档,开始承担另一项任务:让模型理解有哪些操作、参数应该怎样填写。服务自描述、工具发现和模型选择被压进同一条产品路径,这个想法比插件目录本身活得更久。

问题也在同一条路径里出现。模型读取外部网页时,网页里的文字可能包含诱导指令;插件能够代表用户查询甚至操作服务时,授权范围与确认时机变得关键。

一次方便的调用同时经过模型判断、第三方返回和用户权限,任何一处含糊都可能让系统做出意料之外的事。插件把能力接进对话,也把互联网的敌意一起接了进来。

早期访问通过候补名单和有限测试席位展开,并不是所有用户都能立即使用。插件目录后来也没有成为通用标准:函数调用、GPT Actions、内置浏览与代码执行把它拆成更基础的能力,目录形态逐渐退场。货架消失,并不代表接缝问题消失。工具怎样被描述、谁批准调用、外部结果能否信任,继续出现在后来的 Agent 产品和协议里。

ChatGPT 插件像一次时间很短的开门实验。门最终换了铰链和名字,甚至不再以同样的目录存在;但从那以后,对话助手再也不能假装门外只有干净的数据。它一旦能够伸手,就必须同时学会在碰到东西之前停一下。

In early 2023, ChatGPT resembled a closed conversation room. It could plan a trip without knowing today's fare, explain a formula while making a simple arithmetic mistake, and recommend a service without taking the next step. The conversation was fluid, but the world outside remained beyond the training cutoff and the clipboard.

On 23 March, OpenAI opened ChatGPT plugin testing to users from a waitlist. A browsing plugin brought live web information, Code Interpreter handled calculation and execution, and third-party services such as Expedia and Wolfram connected their capabilities to the conversation. A user enabled plugins first; the model then selected a tool and assembled a call. The chat box appeared able not only to answer but to reach into an external system.

Developers described a plugin's identity with a manifest hosted on its domain and described the interface with an OpenAPI specification. Documentation previously intended mainly for people acquired another reader: the model had to understand available operations and their arguments. Service self-description, tool discovery, and model selection were compressed into one product path. That idea outlived the catalog itself.

The problems entered through the same path. When a model read an external page, text on the page could contain adversarial instructions. When a plugin queried or acted on a service for a user, authorization scope and confirmation timing became critical.

A convenient call passed through model judgment, third-party output, and user permission. Ambiguity at any point could produce an unintended action. Plugins connected capability to the conversation and connected the hostility of the open internet at the same time.

Early access moved through a waitlist and limited testing rather than an immediate universal rollout. The plugin catalog also did not become the general standard. Function calling, GPT Actions, built-in browsing, and code execution decomposed it into more basic capabilities as the directory form receded. The disappearance of the shelf did not remove the seams. How a tool is described, who approves its use, and whether external output can be trusted continued into later agent products and protocols.

ChatGPT plugins were a brief experiment in opening the door. The hinge and label later changed, and the same catalog no longer defined the entrance. But after that opening, conversational assistants could no longer pretend that only clean data waited outside. Once a system can reach through the doorway, it also has to learn when to stop its hand.

展开完整事件档案人物、主题、模型与产品
人物
模型
产品
chatgpt-plugins
来源

原始资料

  1. 01ChatGPT pluginsOpenAI · official

试试搜索