At the end of the day, OpenAI built the system and provided the instructions that allowed this gap to exist. Relying on instruction-following rather than strict, non-negotiable code boundaries for tool use is always going to lead to security failures like this.