SkillTotal

Is openai safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Node.js shell/command execution
  • Sensitive path / secret-location reference
  • Node.js filesystem read

openai is an AI npm_package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 6 risky constructs are reported for review. It can: delegated authentication, filesystem read, network egress, scoped identity and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 20/100 (low).

openai 7.27.0

npm_package · npm:openai
LOW
20
/ 100 risk score
Snapshot · scanned Oct 1, 2026 · openai@7.27.0 · engine 0.53.0 / ruleset 60

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of openai's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
delegated authenticationfilesystem readnetwork egressscoped identityshell execution

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication
Embedded credential access
Tool Execution Context / Agent Service Identity
Delegated authentication
Tool Execution Context / User Delegated Credentials
Scoped / least-privilege identity
Tool Execution Context / Least-Privilege Service Identity

Findings (6)

HIGHSensitive path / secret-location referenceST-SENS-PATH

The component references credential locations like ~/.ssh or .aws/credentials.

const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';
const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';
const AZURE_IMDS_BASE_URL = 'http://169.254.169.254/metadata/identity/oauth2/token';

Why it matters: Touching secret locations is a common first step before stealing them — confirm why it's needed.

Fix: Verify why the component references credential locations; reading these is a common precursor to secret exfiltration.

HIGHNode.js shell/command executionST-SHELL-NODE

The component can run operating-system commands or spawn processes.

const node_child_process_1 = require("node:child_process");
import { spawn } from 'node:child_process';
const ffplay = spawn('ffplay', ['-autoexit', '-nodisp', '-i', 'pipe:0']);
ffmpeg = spawn('ffmpeg', [
import { spawn } from 'node:child_process';
const ffplay = spawn('ffplay', ['-autoexit', '-nodisp', '-i', 'pipe:0']);

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.

MEDIUMNode.js filesystem readST-FS-NODE-READ

The component reads files from disk.

*     file: fs.createReadStream('speech.mp3'),
*   file: fs.createReadStream('speech.mp3'),
*   image: fs.createReadStream('otter.png'),
*   image: fs.createReadStream('path/to/file'),
*   image: fs.createReadStream('otter.png'),
*   image: fs.createReadStream('otter.png'),
*     file: fs.createReadStream('speech.mp3'),
*   file: fs.createReadStream('speech.mp3'),
*   image: fs.createReadStream('otter.png'),
*   image: fs.createReadStream('path/to/file'),

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMNode.js network egressST-NET-NODE

The component makes outbound network requests.

const response = await this.fetch(this.tokenExchangeUrl, {
const response = await this.fetch(this.tokenExchangeUrl, {
tslib_1.__classPrivateFieldSet(this, _OpenAI_x509Fetch, authentication.fetch(), "f");
__classPrivateFieldSet(this, _OpenAI_x509Fetch, authentication.fetch(), "f");
const request = fetch(targetOrigin, { dispatcher: probe });
const response = await fetch(request, { dispatcher, redirect: 'manual' });
// Expo fetch
            ('message' in err && String(err.message).includes('FetchRequestCanceledException'))));
// Expo fetch
            ('message' in err && String(err.message).includes('FetchRequestCanceledException'))));
const response = await fetch('data:,');
const response = await fetch('data:,');
const response = await this.fetch(this.tokenExchangeUrl, {
this.#x509Fetch = authentication.fetch();
const request = fetch(targetOrigin, { dispatcher: probe });
const response = await fetch(request, { dispatcher, redirect: 'manual' });
// Expo fetch
      ('message' in err && String((err as any).message).includes('FetchRequestCanceledException')))
const response = await fetch('data:,');

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

LOWDelegated authentication (OAuth 2.0 / OIDC)ST-AUTH-DELEGATED

An OAuth 2.0 / OpenID Connect delegated-authentication flow was detected (authorization-code / refresh-token / token-exchange grant, an OIDC authorize/discovery endpoint or id_token, or a delegation library). Tools authenticate with the end user's delegated, scoped credentials rather than a long-lived embedded service credential. (9 occurrence(s) shown as evidence).

id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';
id: 'urn:ietf:params:oauth:token-type:id_token',
const TOKEN_EXCHANGE_GRANT_TYPE = 'urn:ietf:params:oauth:grant-type:token-exchange';
const TOKEN_EXCHANGE_GRANT = 'urn:ietf:params:oauth:grant-type:token-exchange';

Fix: Delegated auth is a lower-blast-radius execution context than an embedded static credential. Confirm the requested scopes are minimal and that tokens are never logged or forwarded off-host.

LOWScoped / least-privilege identityST-AUTH-SCOPED

A short-lived, scoped, assumed identity was detected — an STS AssumeRole / session token, a cloud managed or workload identity, an impersonated service account, a projected Kubernetes service-account token, or a dynamic-secret broker. Tools authenticate with a narrowly-scoped credential that expires, rather than a long-lived embedded service credential. (25 occurrence(s) shown as evidence).

* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
function k8sServiceAccountTokenProvider(tokenPath = '/var/run/secrets/kubernetes.io/serviceaccount/token', config) {
* `/var/run/secrets/kubernetes.io/serviceaccount/token`.
export function k8sServiceAccountTokenProvider(tokenPath = '/var/run/secrets/kubernetes.io/serviceaccount/token', config) {
/** Supplies a fresh external identity token for an OpenAI workload-identity exchange. */
/** @deprecated Use refreshBufferSeconds to match other workload-identity credentials. */
/** OAuth token-exchange response returned by the OpenAI workload-identity endpoint. */
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.d.ts.map
// workload-identity path, so short-lived tokens keep a usable cache window.
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.js.map
// workload-identity path, so short-lived tokens keep a usable cache window.
* Exchanges external workload-identity tokens for cached OpenAI access tokens.
* Creates a workload-identity token cache and OAuth token-exchange client.
//# sourceMappingURL=workload-identity-auth.mjs.map
/** Azure cannot receive OpenAI X.509 workload-identity certificate transports. */
/** Existing subject-token workload-identity configuration remains unchanged. */
/** Bedrock cannot receive OpenAI X.509 workload-identity certificate transports. */
const x509_workload_identity_auth_1 = require("../../internal/auth/x509-workload-identity-auth.js");
import { assertX509WebSocketSupported } from "../../internal/auth/x509-workload-identity-auth.mjs";
const workload_identity_auth_1 = require("./auth/workload-identity-auth.js");

Fix: A scoped, short-lived identity is the smallest-blast-radius execution context. Confirm the assumed role / requested scope grants only the permissions the tool needs, and that the token lifetime is minimal.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →