Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do

ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do On October 1, 2026, OpenAI's Codex lead Tibo Sottiaux said you can build and deploy MCP servers right through ChatGPT — then restrict access or

ChatGPT Sites Can Host MCP Servers — But Nobody's Gating What the Tools Do

On October 1, 2026, OpenAI's Codex lead Tibo Sottiaux said you can build and deploy MCP servers right through ChatGPT — then restrict access or share them. Plugins lead Max Stoiber confirmed: ChatGPT Sites can host MCP servers, including plugin extensions. By October 3, "Sites in ChatGPT" was front-paged on Hacker News (~209 points, 218 comments).

The hosting how-to is well covered. The missing question: every MCP tool call an agent makes is a small authorization decision — and Sites just removed the hosting tax that kept the callable-tool count low.

Prompt-built servers × paid MCP tools (Cloudflare's Monetization Gateway went closed beta Sept 30 — sellers can charge for MCP tools via x402) × write tools = an authorization problem, not a hosting problem.

The tool-call gate

Install-time review dies when a prompt and a Plus plan ships a server. The authorization has to live at the call:

Call Gate band
Free read-only tool on a private owner-only Site ≥0.80 → auto-call
Paid tool (0.10 USDC/invocation) inside a 5 USDC task budget, unreviewed server 0.50–0.79 → human confirm
Write tool on a shared/unreviewed server <0.50 → block, log, escalate

The hosting tax was never the real tax. The judgment tax is.

Two live gate receipts (Oct 3, 2026)

Scored against the live endpoint POST https://scriptmasterlabs.com/api/harness/decide (local-heuristic-v1, bands 0.80/0.50):

  • Unreviewed paid Sites-hosted tool, 0.10 USDC/invocation, 5 USDC task budget → 0.4045, escalate, block + log
  • Free read-only list_todos, owner-approved task, private owner-only Site → 0.4132, escalate, block + log

Honest finding: the uncalibrated heuristic can't discriminate the free read from the unreviewed paid call — the fail-closed ceiling is the protection. Eighth consecutive run with this finding. "Block everything" is a seatbelt, not judgment; production needs a calibrated decider.

5 steps: gate the tools, not just the install

  1. Keep every new Site private until the tool list is boring — 3 or fewer least-privilege tools, save first, deploy only when boring.
  2. Score the call, not just the server — bands ≥0.80 / 0.50–0.79 / <0.50 at the tool-call boundary.
  3. Per-task budget envelopes for paid tools — 0.10 USDC × 100 calls = 10 USDC. Price is a fact; the envelope is the judgment.
  4. Log instruction, authority, intent, outcome for every paid/write call (the FTC's Sept 30 rogue-agent probe demands exactly this).
  5. Don't outsource judgment to ChatGPT's permission settings — they're UX, not an authorization layer.

Full receipts, the gate table, Claim Receipts and FAQ schema: https://scriptmasterlabs.com/chatgpt-sites-hosted-mcp-servers

Built by ScriptMasterLabs — the x402/MCP/AI pedia. SDVOSB.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.