Field note
OpenAI documents plugins as bundles of skills, connectors, or both, served from one universal directory shared by ChatGPT and Codex, so the same public plugin is discoverable from every supported surface. Installed plugins add skills, connectors and MCP tools to new chats; Codex CLI exposes a plugin browser under /plugins and requires a fresh session before bundled tools appear. The IDE extension does not support plugins at all.
The reach is concrete rather than abstract. The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS, and in Codex and ChatGPT Work it can read and search iMessage, SMS and RCS chats on the user's Mac and send messages on their behalf through the Messages app, while explicitly not offering remote control of ChatGPT through Messages. A plugin directory is therefore also a permission surface: installing an entry can hand an agent read and send access to a personal communication history.
That is the packaging problem several vendors arrived at together, from GitHub Agent Plugins 1.0 standardising portable extensions to Google's Agent Plugins for packaging skills and tools, and it is why the skills hub keeps tracking distribution alongside authoring.
The documentation describes availability and behaviour, not review standards for third-party entries in the shared directory. The condition to watch is whether the universal directory publishes what a plugin must disclose about the data it reads, because one directory feeding two products multiplies the blast radius of a single bad entry.