Microsoft Copilot security directory
OpenAI Assistants (Independent Publisher)
Published by Troy Taylor
High risk
OpenAI Assistants allows you to build AI assistants within your own applications. An Assistant has instructions and can leverage models, tools, and knowledge to respond to user queries. The Assistants service currently supports three types of tools: Code Interpreter, Retrieval, and Function calling.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 27 tools or capabilities.
- Cancel a run
- Create assistant
- Create assistant file
- Create message
- Create run
- Create thread
- Create thread and run
- Delete assistant
- Delete assistant file
- Delete thread
- Get assistant files
- Get run
- Get run step
- Get thread
- List assistants
- List message files
- List messages
- List models
- List run steps
- List runs
- Modify a thread
- Modify message
- Modify run
- Retrieve assistant
The interactive security report will load automatically.