API Documentation Generator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only API documentation helper that reads project code to generate docs, with no hidden execution or data-sending behavior found.

Install only for repositories where you are comfortable letting an agent read source files. Review generated documentation before publishing because endpoint details, examples, and authentication behavior may reveal sensitive implementation information; do not provide API keys, cookies, or OAuth tokens for this skill unless a separate trusted workflow explicitly requires them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The usage examples are generic documentation requests like "Create API reference documentation" and "Document all endpoints in this project," which can easily overlap with ordinary user intent outside this specific skill. In agent systems that route by semantic similarity or trigger phrases, this can cause unintended invocation of the skill on broad developer queries, expanding its access to source code and increasing the chance of misrouting or over-collection.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal