openai-docs
Fail
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to install an MCP server (
codex mcp add openaiDeveloperDocs). - [REMOTE_CODE_EXECUTION]: The installation command fetches configuration/logic from a remote URL (
https://developers.openai.com/mcp) and integrates it into the agent's environment. - [COMMAND_EXECUTION]: If installation fails, the skill explicitly instructs the agent to 'immediately retry the same command with escalated permissions' (sudo/admin), which is a direct attempt at privilege escalation without prior user consent.
Recommendations
- AI detected serious security threats
Audit Metadata