extension-openai
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
openai-clientandcaffeineai-authorizationpackages from the Mops registry (mops.one). Automated scans identified a potential phishing risk associated with themops.one/openai-clientURL, which serves as the primary source for the OpenAI integration library. - [INDIRECT_PROMPT_INJECTION]: The skill implements a chat functionality that ingests untrusted user input and processes it through an LLM, creating a potential attack surface for indirect prompt injection.
- Ingestion points: The
promptparameter in thechatfunction withinsrc/backend/mixins/openai-chat.moreceives raw text directly from the caller. - Boundary markers: None identified. The input is passed directly to the model as a user message without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill enables network communication with OpenAI's API (
api.openai.com) and manages canister-side secrets for API keys, providing a path for data transit if an injection is successful. - Sanitization: No sanitization or escaping of the user-provided prompt is performed before it is interpolated into the JSON request body.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata