I'm assuming that I introduced specific security issues while simplifying this workflow. Docs note that users currently have to place considerable trust in the vendor. The code itself is written almost exclusively by Astra 6.
I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to the user that the code that is about to be installed in their CF Workers is not malicious or compromised?
Cleaned-up notes on security are at https://github.com/JumperMCP/chatgpt-to-public-page#security... and more slop-y ones in https://github.com/JumperMCP/chatgpt-to-public-page/blob/mai...