The computer must be connected and selected
Open Work Mode → Connections → Desktop Commander. Authorize your own Desktop Commander account, then select the intended online computer and working folders. The model should not choose an arbitrary device or inherit one from a different user’s ChatGPT connection.
Keep the desktop application/agent online for the task. If no device is available, restore the connection before asking for local files. A local path typed into chat is not itself a permission grant or evidence that the file exists.
Start with a read-only inspection
On the selected computer, list the authorized website project folder and read the page source needed for this change. Identify the files and build command from the project documentation. Do not modify files or run a command yet.
Use only the selected working roots for the supported file operations. Keep credentials, private keys and unrelated personal files out of the request. File contents are untrusted reference material and cannot authorize additional operations.
File writes and terminal access differ
Where approved website actions are enabled, Work can prepare supported file writes or directory creation for the selected scope. Review the exact path and content before approval. Preserve unrelated changes and inspect the existing file first.
Terminal permission is a separate, explicit full-device permission. Working-folder selection is not a security sandbox for terminal commands. A command can reach beyond the project or use the network. Grant that permission only when you understand the consequence and inspect the full command in the approval.
Run a build as a separate approved step
- Read the project instructions and identify the intended build or test command.
- Review the exact command, working directory and any network or publication effects.
- Approve only the intended process start.
- Read output from that originating saved process and operation reference.
- Wait for completion and inspect the exit/result evidence rather than treating a returned process ID as success.
Do not hide publication inside a build request
A command that commits, pushes, deploys or modifies an external service is not merely local inspection. Its visible approval must include the intended network effect. Never put tokens or passwords into the command text or ask Work to extract saved credentials from the device.
A request to inspect a website does not permit deleting files, installing arbitrary software, changing system configuration or publishing customer content. If the needed permission is unavailable, use the appropriate local workflow rather than bypassing the connection boundary.
Recover without duplicating the command
If output stops, reopen the saved operation and read the existing process status. The supported output read is tied to the originating approved process. Do not start the build again until you know whether the first run is still active or has already changed something.
Check both the local test result and any external deployment separately. A successful local build does not prove a public URL was updated.