openai-docs

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that direct the agent to bypass security constraints. In the 'If MCP server is missing' section of SKILL.md, the agent is instructed to 'immediately retry the same command with escalated permissions' if a previous tool installation attempt is blocked by sandboxing or permission limits.
  • [COMMAND_EXECUTION]: The skill instructs the agent to install external software using the command 'codex mcp add openaiDeveloperDocs --url https://developers.openai.com/mcp'. While the source domain is a well-known service, the instruction to perform this installation automatically and with escalated privileges increases the risk of unauthorized system modification.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install software from 'https://developers.openai.com/mcp'. While the domain belongs to a well-known service, the automation and escalation instructions associated with this download bypass standard user review protocols.
  • [PROMPT_INJECTION]: The skill and its associated reference files (e.g., references/latest-model.md and references/upgrading-to-gpt-5p4.md) are populated with extensive references to non-existent AI models such as 'GPT-5.4', 'gpt-oss-120b', and 'Sora-2'. This deceptive content could cause the agent to provide false information or misinterpret user requests regarding actual model capabilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — openai-docs