openai-docs
Fail
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The instructions in
SKILL.mdexplicitly direct the agent to retry MCP server installation commands with "escalated permissions" if an initial attempt is blocked by security or permission constraints. - [COMMAND_EXECUTION]: The helper script
scripts/fetch-codex-manual.mjsexecutescurlorcurl.exeviaexecFile, which allows the agent to run system binaries to fetch content. - [EXTERNAL_DOWNLOADS]: The skill fetches documentation and update information from OpenAI developer domains (
developers.openai.com). These references are documented here as part of the skill's normal operation to maintain up-to-date documentation. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external Markdown content from remote URLs which could potentially introduce untrusted instructions.
- Ingestion points: Documentation is fetched using
scripts/fetch-codex-manual.mjsandscripts/resolve-latest-model-info.js. - Boundary markers: The skill does not implement specific delimiters or warnings to isolate the fetched external content from the model's instruction logic.
- Capability inventory: The skill can execute shell commands (
curl) and perform file system operations (write to cache). - Sanitization: The documentation fetcher performs SHA-256 hash validation to verify the integrity of the downloaded manual.
Recommendations
- AI detected serious security threats
Audit Metadata