agents-docs

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes a bundled bash script to fetch documentation from official sources, including developers.openai.com and learn.chatgpt.com. These domains are official repositories for the documented products.
  • [REMOTE_CODE_EXECUTION]: The skill executes its own helper utility, scripts/fetch-doc.sh, to manage documentation artifacts. The script is well-structured for security, employing restricted permissions via umask 077, strictly limiting redirections to official domains, and validating content integrity with specific markers.
  • [COMMAND_EXECUTION]: The skill provides instructions to execute the codex CLI for administrative and documentation tasks, such as checking feature lists, validating configuration files, and generating JSON schemas. These operations are consistent with the skill's stated purpose of assisting with Codex product questions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation fetched from the web, which constitutes an ingestion surface. This is addressed by: 1) Ingestion points: Documentation is fetched via fetch-doc.sh from official URLs; 2) Boundary markers: Instructions direct the agent to read only specific heading ranges and paraphrase content; 3) Capability inventory: The agent can execute the codex tool and the local fetch script; 4) Sanitization: The fetch script validates the presence of official content markers before accepting a download.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:07 PM