Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-focused OpenAPI/Swagger helper skill with no executable code, persistence, credential handling, or hidden data flows.

Safe to install for OpenAPI/Swagger documentation help. Users should be aware it may activate for general API documentation or developer-experience requests; tightening trigger text would make invocation more predictable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger phrases are generic and templated enough that they can match ordinary user requests without a clear opt-in, increasing the chance the skill is invoked when the user did not explicitly request it. In an agent environment, unintended invocation can route conversations into the wrong workflow, causing irrelevant actions, disclosure of unnecessary context to the skill, or policy bypass via overly broad activation conditions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and generic enough that normal user requests about APIs, Swagger, or documentation could activate this skill unintentionally. Over-broad routing can cause prompt/skill hijacking at the orchestration layer, leading the agent to apply this skill in contexts where it is not the best fit and potentially exposing user data or causing incorrect actions.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description and usage guidance are broad enough that the skill may activate for loosely related requests, causing unintended routing or over-application of the skill. In an agent environment, ambiguous activation boundaries can expose users to irrelevant instructions, reduce predictability, and increase the chance that a more sensitive request is handled by the wrong skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The keyword triggers include generic terms like 'software-and-data' and broad API-related phrases without sufficient qualifiers, which can cause accidental invocation for unrelated development tasks. This expands the skill's reach beyond its intended domain and can interfere with correct skill selection or policy enforcement.

Vague Triggers

Low
Confidence
76% confidence
Finding
The example trigger phrases are malformed and fail to communicate precise, safe activation boundaries, which can confuse downstream routing logic or maintainers about the intended invocation conditions. While not directly exploitable like code execution, poor trigger examples increase misclassification risk and reduce operational safety in multi-skill systems.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger description is broad and loosely bounded: it activates for a wide set of topics like software-and-data, openapi, swagger, api documentation, and rest api without clear exclusion criteria. This can cause the skill to be invoked outside its intended scope, leading to incorrect delegation, reduced analyst/user control, and possible exposure of unrelated user content to a skill not specifically needed for the task.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword list and example triggers lack scope constraints and negative examples, so common terms like openapi, swagger, rest api, and developer experience may match many unrelated requests. In an agent setting, ambiguous triggers increase the chance of unintended activation, misrouting, and over-application of the skill's workflow to requests that do not actually concern API documentation generation or validation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains a very generic activation phrase ('Use $openapi-docs-generator to help me...') tied to common software and API documentation requests, which increases the chance of implicit or accidental invocation during normal conversation. Because implicit invocation is enabled, this broad phrasing can cause the skill to activate outside clearly intentional contexts, potentially exposing users to unintended prompt injection surface or unexpected agent behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of accidental routing, prompt-context injection into unrelated tasks, and reduced user control over when this skill is invoked.

Vague Triggers

Medium
Confidence
91% confidence
Finding
A vague invocation pattern without scope constraints can make the system select this skill for loosely related requests, including ones that do not actually concern API documentation. This creates misrouting risk and may expose users to irrelevant or unintended instructions, especially in agentic environments where tool choice influences downstream actions.

Vague Triggers

Low
Confidence
89% confidence
Finding
The activation guidance is underspecified and includes malformed trigger examples, which can lead to unreliable or unintended activation behavior. While not directly enabling code execution or data exfiltration, poor trigger hygiene weakens routing integrity and can compound other prompt-selection weaknesses.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.