Currently anyone can access the files, you just have to ask for a download link in some twisted way ^^: https://chat.openai.com/share/c6209014-57a6-4da7-979b-673c2802fc61
I find the problem not so obvious, concretely a custom GPT’s purpose is to expose the data it has access to, is it very different to access the files? The only problem I can see is the copyrighted files that can be accessed.
But technically, I wonder why ChatGPT needs to expose files in this way to work.
On the other hand, I wonder how gptshunter goes about extracting file names, since the API apparently doesn’t allow access to GPTs (Access to new custom "My GPTs" through API? - #3 by zacharytaylorjohnson).