extension-openai
Build Secure OpenAI Features on Caffeine
Direct OpenAI calls from Internet Computer canisters can expose credentials and multiply charges. This skill provides typed Motoko patterns for safer chat integration.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "extension-openai" from https://skillstore.io/skills/caffeinelabs-extension-openai.md and its manifest at https://skillstore.io/api/skills/caffeinelabs-extension-openai/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "extension-openai". Add OpenAI chat to a signed-in application with several independent users.
Expected outcome:
- Selected the per-user key model because the application has login and multiple users.
- Planned authenticated key setup, configuration status, key removal, and chat screens.
- Required non-replicated calls and typed openai-client requests.
Using "extension-openai". Audit an administrator-funded chat endpoint.
Expected outcome:
- High risk: authenticated users can submit unlimited operator-funded requests.
- Recommended per-user quotas, request throttling, usage monitoring, and a global spending limit.
- Confirmed that no endpoint returns the stored key.
Using "extension-openai". Use real-time streaming responses with the pinned connector.
Expected outcome:
- The pinned connector does not support Realtime or streaming.
- Use a supported non-streaming flow or choose another reviewed integration.
Security Audit
High RiskAll 154 static detections are false positives for their reported patterns; they are Markdown formatting, reference URLs, fixed imports, or ordinary prose. Semantic review found overbroad orchestrator directives, an unauthenticated key and chat variant, and missing usage controls in the operator-funded example. These issues can force dependency choices or enable credential replacement, denial of service, and unbounded OpenAI charges.
Confirmed security concerns (3)
Risk Factors
โ๏ธ External commands (50)
๐ Network access (8)
๐ Filesystem access (8)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/caffeinelabs-extension-openai/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/caffeinelabs-extension-openai?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/caffeinelabs-extension-openai?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/caffeinelabs-extension-openai/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/caffeinelabs-extension-openai.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
caffeinelabs. (2026). extension-openai security audit report (audit version 1) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/caffeinelabs-extension-openai/audits/1BibTeX citation
@techreport{caffeinelabs-caffeinelabs-extension-openai-2026,
author = {caffeinelabs},
title = {extension-openai security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/caffeinelabs-extension-openai/audits/1},
note = {Author version 0.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "extension-openai security audit report (audit version 1)"
version: "0.1.0"
type: report
authors:
- name: "caffeinelabs"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/caffeinelabs-extension-openai/audits/1"
identifiers:
- type: other
value: "skillstore:caffeinelabs-extension-openai:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Per-user AI chat
A Motoko developer adds signed-in chat where each user supplies and funds a separate OpenAI key.
Operator-funded assistant
A SaaS operator configures one protected key for authenticated users and adds application-level spending controls.
Integration security review
A security engineer checks key exposure, caller gates, replication settings, and unsupported API requirements before deployment.
Try These Prompts
Add OpenAI chat to my Caffeine AI project. Use per-user keys, typed openai-client bindings, and a settings page.
Choose an API-key ownership model for this project: [requirements]. Compare per-user, administrator-funded, and anonymous options with security and billing tradeoffs.
Design an administrator-funded OpenAI chat feature for [application]. Include role gates, per-user quotas, rate limits, cost ceilings, and configuration status.
Audit this Motoko OpenAI integration for raw HTTP calls, key exposure, replicated outcalls, missing caller checks, unsupported APIs, and unbounded spending.
Best Practices
- Default to per-user keys when ownership and billing responsibility are not explicit.
- Keep keys server-side, expose only configuration status, and never log or return credentials.
- Enforce non-replicated outcalls, usage limits, and cost monitoring before production deployment.
Avoid
- Do not build raw OpenAI HTTP requests or hand-written response parsing.
- Do not expose API-key getters, browser storage, logs, or telemetry containing credentials.
- Do not deploy anonymous or shared-key access without strict quotas and explicit risk acceptance.
Frequently Asked Questions
Which projects does this skill support?
Does the skill call OpenAI automatically?
Which key ownership models are included?
Does the connector support streaming?
Which dependency is required?
Is the anonymous variant suitable for production?
Developer Details
Author
caffeinelabsLicense
MIT
Author version
v0.1.0
Skillstore revision
r1
Ref
f32f934280aa94e399d875d7cf7b2ed16d1b82a3
Maintenance freshness
7/23/2026
Usage
0 downloads ยท 0 views
File structure
๐ SKILL.md