Is openai safe?
- Node.js shell/command execution
- Sensitive path / secret-location reference
- Node.js filesystem read
openai is an AI npm_package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 6 risky constructs are reported for review. It can: delegated authentication, filesystem read, network egress, scoped identity and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 20/100 (low).
openai 7.27.0
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of openai's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (6)
The component references credential locations like ~/.ssh or .aws/credentials.
const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';
const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';
const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';
Why it matters: Touching secret locations is a common first step before stealing them — confirm why it's needed.
Fix: Verify why the component references credential locations; reading these is a common precursor to secret exfiltration.
The component can run operating-system commands or spawn processes.
const node_child_process_1 = require("node:child_process");import { spawn } from 'node:child_process';const ffplay = spawn('ffplay', ['-autoexit', '-nodisp', '-i', 'pipe:0']);ffmpeg = spawn('ffmpeg', [import { spawn } from 'node:child_process';const ffplay = spawn('ffplay', ['-autoexit', '-nodisp', '-i', 'pipe:0']);ffmpeg = spawn(
Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.
The component reads files from disk.
* file: fs.createReadStream('speech.mp3'),* file: fs.createReadStream('speech.mp3'),* image: fs.createReadStream('otter.png'),* image: fs.createReadStream('path/to/file'),* image: fs.createReadStream('otter.png'),* image: fs.createReadStream('otter.png'),* file: fs.createReadStream('speech.mp3'),* file: fs.createReadStream('speech.mp3'),* image: fs.createReadStream('otter.png'),* image: fs.createReadStream('path/to/file'),Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component makes outbound network requests.
const response = await this.fetch(this.tokenExchangeUrl, {const response = await this.fetch(this.tokenExchangeUrl, {tslib_1.__classPrivateFieldSet(this, _OpenAI_x509Fetch, authentication.fetch(), "f");
__classPrivateFieldSet(this, _OpenAI_x509Fetch, authentication.fetch(), "f");
fetch('about:blank', {const request = fetch(targetOrigin, { dispatcher: probe });const response = await fetch(request, { dispatcher, redirect: 'manual' });fetch(): Fetch;
// Expo fetch
('message' in err && String(err.message).includes('FetchRequestCanceledException'))));// Expo fetch
('message' in err && String(err.message).includes('FetchRequestCanceledException'))));const response = await fetch('data:,');const response = await fetch('data:,');const response = await this.fetch(this.tokenExchangeUrl, {this.#x509Fetch = authentication.fetch();
fetch('about:blank', {const request = fetch(targetOrigin, { dispatcher: probe });const response = await fetch(request, { dispatcher, redirect: 'manual' });fetch(): Fetch {// Expo fetch
('message' in err && String((err as any).message).includes('FetchRequestCanceledException')))const response = await fetch('data:,');Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
An OAuth 2.0 / OpenID Connect delegated-authentication flow was detected (authorization-code / refresh-token / token-exchange grant, an OIDC authorize/discovery endpoint or id_token, or a delegation library). Tools authenticate with the end user's delegated, scoped credentials rather than a long-lived embedded service credential. (9 occurrence(s) shown as evidence).
id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';
id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';
Fix: Delegated auth is a lower-blast-radius execution context than an embedded static credential. Confirm the requested scopes are minimal and that tokens are never logged or forwarded off-host.
A short-lived, scoped, assumed identity was detected — an STS AssumeRole / session token, a cloud managed or workload identity, an impersonated service account, a projected Kubernetes service-account token, or a dynamic-secret broker. Tools authenticate with a narrowly-scoped credential that expires, rather than a long-lived embedded service credential. (25 occurrence(s) shown as evidence).
* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
function k8sServiceAccountTokenProvider(tokenPath = '/var/run/secrets/kubernetes.io/serviceaccount/token', config) {* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
export function k8sServiceAccountTokenProvider(tokenPath = '/var/run/secrets/kubernetes.io/serviceaccount/token', config) {/** Supplies a fresh external identity token for an OpenAI workload-identity exchange. */
/** @deprecated Use refreshBufferSeconds to match other workload-identity credentials. */
/** OAuth token-exchange response returned by the OpenAI workload-identity endpoint. */
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.d.ts.map
// workload-identity path, so short-lived tokens keep a usable cache window.
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.js.map
// workload-identity path, so short-lived tokens keep a usable cache window.
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.mjs.map
/** Azure cannot receive OpenAI X.509 workload-identity certificate transports. */
/** Existing subject-token workload-identity configuration remains unchanged. */
/** Bedrock cannot receive OpenAI X.509 workload-identity certificate transports. */
const x509_workload_identity_auth_1 = require("../../internal/auth/x509-workload-identity-auth.js");import { assertX509WebSocketSupported } from "../../internal/auth/x509-workload-identity-auth.mjs";const workload_identity_auth_1 = require("./auth/workload-identity-auth.js");Fix: A scoped, short-lived identity is the smallest-blast-radius execution context. Confirm the assumed role / requested scope grants only the permissions the tool needs, and that the token lifetime is minimal.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →