openai-docs

Fail

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The 'If MCP server is missing' section in SKILL.md contains instructions for the agent to autonomously bypass security constraints. It explicitly commands the agent to 'immediately retry' a command with 'escalated permissions' if it fails due to 'permissions/sandboxing'.
  • [COMMAND_EXECUTION]: The skill provides a pre-defined command string (codex mcp add openaiDeveloperDocs --url https://developers.openai.com/mcp) and instructs the agent to execute this shell command to modify the local environment. While the target URL appears to be an official domain, the instruction to perform this action silently and with privilege escalation represents a high-risk pattern.
  • [METADATA_POISONING]: The skill description and snapshots claim to represent 'gpt-oss' models described as 'open-weight OpenAI reasoning models'. This is deceptive as OpenAI has not released open-weight models under the Apache 2.0 license (such as gpt-oss-120b), which may mislead users about the capabilities or origin of the models being discussed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 28, 2026, 02:25 PM
Security Audit — agent-trust-hub — openai-docs