ChatGPT Agent
OpenAI's computer-use agent inside ChatGPT. Browses, clicks, fills forms, and executes tasks in a virtual browser. The most consumer-friendly agent in the wild.
Delv Safety Grade: B
Score 72/100 · assessed 2026-04-18
OpenAI's ChatGPT Agent is a major vendor product with strong organisational backing, but it operates with broad desktop-like permissions in a virtual browser environment. The maintainer score is excellent given OpenAI's scale and resources. However, the permissions model is concerning: it can browse arbitrary sites, fill forms, click buttons, and handle credentials within its sandboxed browser. The supply chain is solid as a hosted service requiring ChatGPT Plus/Pro subscription, avoiding local installation risks. Transparency suffers from closed-source implementation and limited technical documentation about safety boundaries. The incident score reflects one known issue where early users reported the agent accessing unintended sites during task execution. This is a polished consumer product, but the broad autonomy and closed implementation warrant careful use, especially for sensitive tasks involving credentials or financial transactions.
Green flags
- Backed by OpenAI with substantial security resources
- Sandboxed virtual browser limits host system access
- Integrated into ChatGPT Plus/Pro with existing account controls
- No local installation or supply chain complexity
Red flags
- Closed-source implementation with no code audit possible
- Can interact with any website including credential entry
- Limited documentation on safety boundaries and data retention
- Early reports of unintended site access during task execution
- No local control or ability to restrict browsing scope
Permissions requested
Pricing
Platforms
Review
The easiest autonomous agent to start using today, and the only one your non-technical colleagues might actually adopt. Best for repetitive public web tasks; skip it if you need enterprise integrations or sub-second performance.
Good at
- Zero setup - works immediately for any ChatGPT Plus subscriber
- Handles messy, real-world web pages better than most scrapers
- Natural language tasking means no scripting required
- Recovers gracefully from layout changes and minor obstacles
- Included in existing ChatGPT subscription, no separate billing
Watch out
- Slower than manual execution for simple tasks
- Limited to public web - no private tools or local file access
- Pauses frequently for confirmation on sensitive actions
- Cannot chain with external APIs or automation platforms
- Struggles with aggressive bot detection and complex checkout flows
Use cases
- Booking reservations from a natural-language prompt
- Filling complex web forms that rotate every month
- Pulling data from sites without APIs
- Executing multi-step purchases with oversight