Back to skill

Security audit

open ai api

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only OpenAI API usage guide with disclosed costs and data-sharing considerations, not a hidden or self-executing capability.

Install only if you intend the agent to use OpenAI API tools with a billed API key. Review sensitive documents before embedding or sending them, avoid secrets and regulated personal data unless your organization has approved that use, set spend limits, and require clear user intent before using broad openai_request operations such as uploads, file deletion, fine-tuning, or vector-store changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recipe explicitly instructs sending source document chunks and user queries to external API tools for embeddings and chat, but it provides no warning about privacy, data classification, consent, retention, or redaction. In a RAG workflow, source documents often contain proprietary or personal data, so omission of handling guidance can cause unintentional disclosure to third-party services even if the technical pattern is otherwise standard.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · reference/common-errors.md (reported line 29)May include surrounding context.

md
## Retries

The MCP server auto-retries `429`/`5xx` up to `OPENAI_MAX_RETRIES` (default 3). It does NOT retry `401`/`400`. Set `OPENAI_MAX_RETRIES=0` to handle retries yourself.

> Verification needed: confirm error codes with <https://platform.openai.com/docs/api-reference>.

Static analysis

No suspicious patterns detected.