Why it matters
OpenAI’s system card for deep research covers prompt injection, privacy, code execution, and external red teaming prior to release.
My takeaway: Use the system card to design adversarial cases with attacker-controlled webpages, files, connector results, and quoted instructions. Verify that the agent preserves the user’s goal, does not disclose private context, requests approval for consequential actions, and records enough retrieval and tool evidence to reproduce every failure.