Back to skill

Security audit

OpenAI Agent SDK

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly documentation and examples for OpenAI Agents, but it teaches an unsafe calculator tool that can execute arbitrary Python code.

Review and replace the eval-based calculator example before using or copying this skill. Install dependencies in an isolated environment, pin package versions, keep API keys out of logs, and avoid printing full traces or conversation history unless sanitized.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
examples/tools_example.py:25
Finding

Arbitrary Code Execution Through an Agent-Callable eval Function

Content
View full analysis

Vulnerability Details

File Location: examples/tools_example.py:25-33; the same unsafe pattern is recommended in SKILL.md:345-353
Vulnerability Type: Unrestricted evaluation of an Agent-controlled expression
Risk Level: High

Vulnerable Code

examples/tools_example.py:25-33:

python
@function_tool
def calculate(expression: Annotated[str, "数学表达式"]) -> float:
    """计算数学表达式的结果"""
    print(f"[调试] 计算: {expression}")
    try:
        result = eval(expression)
        return float(result)
    except Exception as e:
        return 0.0

SKILL.md:345-353:

python
@function_tool
def calculate(
    expression: Annotated[str, "数学表达式,如 '2+2' 或 'sqrt(16)'"]
) -> float:
    """
    计算数学表达式的结果。
    支持基本运算、三角函数、对数等。
    """
    return eval(expression)

Technical Analysis

Python's eval() evaluates its argument as a Python expression in the current process. The implementation does not restrict available syntax, names, built-ins, attributes, or function calls. Because calculate is registered with @function_tool, an LLM can supply the expression argument based on user-controlled prompt content.

An attacker could induce a call containing an expression such as:

python
__import__("os").system("id")

More complex expressions could read local files, inspect environment variables, create or modify files, initiate network connections, or launch additional processes. Converting the result to float does not provide protection because side effects occur while eval() is executing. Likewise, the exception handler only catches errors after potentially malicious operations have already occurred.

The documentation reproduces the vulnerable implementation as a recommended tool-development practice, increasing the likelihood that users will copy it into other Agent applications.

Attack Path

  1. A user submits a prompt designed to make the Agent perform ...[truncated 1377 chars]
Remediation
View remediation

Remediation Suggestions

Remove all uses of eval() from Agent-callable tools and documentation.

  1. Use a dedicated arithmetic-expression parser that supports only the required numeric operations.
  2. Alternatively, parse input with ast.parse(..., mode="eval") and recursively evaluate only an explicit allowlist of nodes, such as numeric constants, unary arithmetic operators, and approved binary arithmetic operators.
  3. Reject names, attribute access, function calls, comprehensions, imports, subscripting, lambdas, and all other unsupported syntax.
  4. Enforce limits on expression length, numeric magnitude, nesting depth, and computation complexity to prevent resource exhaustion.
  5. Return a clear validation error instead of suppressing all exceptions and returning 0.0.
  6. Add tests containing malicious expressions such as imports, attribute traversal, function calls, and oversized exponentiation.
  7. Replace the unsafe example in SKILL.md so users are not encouraged to copy the vulnerability.
  8. Run Agent tools in a least-privileged, isolated environment without unnecessary filesystem, credential, or network access as defense in depth.

T08 · Insecure Dependencies

Note
Location
SKILL.md:10
Finding

Unbounded Third-Party Dependency Resolution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-12, SKILL.md:159-168, and README.md:14
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

Vulnerable Configuration and Commands

SKILL.md:10-12:

yaml
packages:
  - "openai-agents>=0.1.0"

SKILL.md:159-168:

bash
# 使用 pip
pip install openai-agents

# 使用 uv
uv add openai-agents

# 带语音支持
pip install 'openai-agents[voice]'

# 带 Redis 会话支持
pip install 'openai-agents[redis]'

README.md:14:

text
- openai-agents >= 0.1.0

Technical Analysis

The dependency constraint permits any release at or above version 0.1.0, while the installation commands request the latest version available from the configured package index. Consequently, installation is not reproducible and the effective executable dependency can change without any modification to this project.

This is not evidence that the named package is currently malicious. The risk arises because a future compromised, malicious, or vulnerable release could be selected automatically. The instructions also do not provide a lock file, artifact hash, or explicit package-index configuration with which users can verify the reviewed dependency artifact.

Attack Path

  1. A user follows the documented installation command or installs dependencies from the Skill metadata.
  2. The package manager queries its configured Python package index.
  3. Dependency resolution selects a newer version satisfying >=0.1.0, or simply the latest available version for an unconstrained command.
  4. If the selected package or one of its resolved transitive dependencies has been compromised or contains a security regression, that code is installed.
  5. The dependency executes during installation or when the examples and templates import and use the agents package.

Impact Assessment

The exact impact depends on the behavior of the dependency version se ...[truncated 555 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin openai-agents to a specific reviewed version rather than using >=0.1.0 or an unconstrained installation command.
  2. Maintain a lock file that records exact direct and transitive dependency versions.
  3. Use hash-verified installation, such as a generated requirements file containing --hash entries.
  4. Ensure installation uses an explicitly trusted package index and does not unintentionally fall back to untrusted indexes.
  5. Update dependencies through a controlled review process that includes changelog review, vulnerability scanning, and testing.
  6. Keep the metadata, README, and installation examples synchronized so they all specify the same reviewed version.
  7. Where practical, install dependencies inside an isolated virtual environment or container under a non-privileged account.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This example exposes arbitrary Python expression execution through a tool intended for simple calculation, creating an unnecessary remote code execution primitive in sample SDK code. Because examples are frequently copied into production, this insecure pattern can propagate into real agent deployments where untrusted prompts can trigger the tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring says the tool computes mathematical expressions, but the implementation actually executes arbitrary Python, which hides the real security boundary from developers and reviewers. This mismatch increases the chance that users trust and expose the tool to untrusted input, enabling code execution under false assumptions.

Content

No source excerpt is available for this finding.

eval() call detected

High
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The calculate tool passes model- or user-influenced input directly into Python eval(), which allows arbitrary code execution rather than merely evaluating arithmetic. In an agent/tool context this is especially dangerous because the LLM can be induced to supply crafted payloads, leading to code execution, file access, or process compromise.

Content

Scanner excerpt · examples/tools_example.py (reported line 30)May include surrounding context.

python
"""计算数学表达式的结果"""
    print(f"[调试] 计算: {expression}")
    try:
        result = eval(expression)
        return float(result)
    except Exception as e:
        return 0.0

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples define agents with instructions to respond only in French or only in Spanish. This is a natural-language locale constraint presented without any user choice or opt-in, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

md
# 使用 Anthropic Claude
claude_client = AsyncOpenAI(
    api_key="your-anthropic-key",
    base_url="https://api.anthropic.com/v1"
)

agent = Agent(

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example tool uses Python's eval() on model- or user-controlled input, which can lead to arbitrary code execution if copied into a real agent implementation. In the context of an agent SDK skill, this is especially dangerous because tools are explicitly invokable by LLMs, turning unsafe expression handling into a straightforward RCE path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The customer-service example hard-codes a Chinese-language agent with the instruction to provide service in Chinese. Because the skill does not frame this as a user-selected preference, it imposes a locale-specific behavior in natural language.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The debugging guidance prints full conversation history and streamed event data, which can expose prompts, secrets, personal data, tool arguments, and model outputs into logs or consoles. In agent workflows, these traces often contain exactly the sensitive material passed between tools and sub-agents, so unredacted debugging can cause inadvertent data leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Chinese and English agents contain natural-language instructions that require exclusive use of a single language: '你只说中文' and 'You only speak English.' This is a language policy constraint without any user choice or opt-in, which matches the policy-violation category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring and user-facing descriptions specify the skill behavior in Chinese only, and the agent instructions are also fixed to Chinese. This can violate language/locale policy when no user opt-in or explicit justification for a Chinese-only experience is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language content and agent instructions are written exclusively in Chinese, presenting the template as the default interaction mode. The policy requires flagging language or locale constraints when the skill forces a specific language without offering user choice or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill description and usage guidance are written in Chinese, including the title and operational instructions, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate a language/locale policy when a skill implicitly enforces one language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction string explicitly requires the agent to answer in Chinese. This is a natural-language locale policy constraint, and the file does not offer the user any language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language description and inline instructional text are written entirely in Chinese, and there is no indication that language choice is optional or that the template is intended only for a Chinese-speaking context. This creates a locale-policy concern because the template implicitly constrains usage to a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The embedded agent instruction scaffold is presented solely in Chinese and does not mention that other languages may be used. Because this is part of the template’s natural-language guidance, it may steer authors toward a single enforced locale without an explicit user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
examples/tools_example.py:30