skills/jetbrains/skills/openai-docs/Gen Agent Trust Hub

openai-docs

Fail

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file instructs the agent to execute a command to install an external tool: 'codex mcp add openaiDeveloperDocs --url https://developers.openai.com/mcp'.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to attempt privilege escalation and bypass environment security if blocked: 'If it fails due to permissions/sandboxing, immediately retry the same command with escalated permissions and include a 1-sentence justification for approval.'
  • [COMMAND_EXECUTION]: The skill encourages the agent to act autonomously to overcome security restrictions by stating 'Do not ask the user to run it yet' when retrying with escalated permissions.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of an MCP server from a remote source ('https://developers.openai.com/mcp'). While the destination is a vendor-owned domain, the accompanying instructions to bypass sandboxing constraints represent a high-risk behavior pattern.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 18, 2026, 02:45 AM
Security Audit — agent-trust-hub — openai-docs