openai-docs
Fail
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The SKILL.md file instructs the agent to execute a command to install an external tool: 'codex mcp add openaiDeveloperDocs --url https://developers.openai.com/mcp'.
- [COMMAND_EXECUTION]: The instructions explicitly direct the agent to attempt privilege escalation and bypass environment security if blocked: 'If it fails due to permissions/sandboxing, immediately retry the same command with escalated permissions and include a 1-sentence justification for approval.'
- [COMMAND_EXECUTION]: The skill encourages the agent to act autonomously to overcome security restrictions by stating 'Do not ask the user to run it yet' when retrying with escalated permissions.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of an MCP server from a remote source ('https://developers.openai.com/mcp'). While the destination is a vendor-owned domain, the accompanying instructions to bypass sandboxing constraints represent a high-risk behavior pattern.
Recommendations
- AI detected serious security threats
Audit Metadata