openai-docs

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md direct the agent to bypass initial permission failures by immediately retrying commands with escalated permissions during tool setup. This encourages the agent to seek ways to circumvent security restrictions.\n- [PRIVILEGE_ESCALATION]: The skill explicitly advises the agent to seek 'escalated permissions' if tool installation fails due to sandboxing or permission issues, which is a potential risk to the host environment.\n- [DYNAMIC_EXECUTION]: Core functionality relies on the execution of multiple local scripts distributed with the skill, including 'resolve-latest-model-info' and 'fetch-codex-manual.mjs', using system sh and Node.js runtimes.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests external content to drive logic like model selection and prompting guidance.\n
  • Ingestion points: Markdown documentation fetched from developers.openai.com.\n
  • Boundary markers: None explicitly defined beyond header-based extraction.\n
  • Capability inventory: Includes shell command execution, tool calls, and file system writes.\n
  • Sanitization: No sanitization or validation of the remote content is mentioned.\n- [EXTERNAL_DOWNLOADS]: Fetches documentation and tool configuration from OpenAI's official developer domains, which are recognized as trusted services.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — openai-docs