Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation workflow skill for OpenAPI/Swagger work, with no executable code, persistence, credential handling, or hidden data movement found.

Before installing, be aware that the skill may activate for some broad API or developer-experience requests, so review whether it is the right workflow when your request is not specifically about OpenAPI, Swagger, REST API documentation, or validation. I found no evidence of malicious behavior or unsafe persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic and malformed enough to match broad user requests about OpenAPI, Swagger, or practical workflows, which can cause the skill to activate when the user did not explicitly intend to invoke it. Unintended invocation is a security and safety concern because it can route users into a skill-specific instruction set and workflow without clear consent, increasing the chance of prompt-scope confusion or misuse of the skill in unrelated contexts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and map to very common API-documentation requests, which increases the chance this skill activates in situations where the user did not specifically intend to invoke it. Over-broad activation can cause prompt/skill hijacking at routing time, leading the agent to apply this workflow instead of a more appropriate or safer capability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description activates on broad categories like 'software-and-data' and general OpenAPI/Swagger terms without enough boundary conditions. This can cause unintended invocation for loosely related requests, increasing the chance the agent applies the skill in the wrong context and produces irrelevant or unsafe guidance based on mistaken routing.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include generic terms such as 'software-and-data' and 'developer experience' that are not specific to this skill's function. Overbroad keyword matching can misroute unrelated user requests into this skill, leading to poor task selection, reduced safety controls, and accidental disclosure or generation of content outside the intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough that it could activate for many generic software or API-documentation requests without clearly limiting when it should be used. Over-broad routing can cause the wrong skill to handle prompts, leading to irrelevant guidance, missed safeguards from more appropriate skills, or increased exposure to prompt-confusion and policy-bypass opportunities.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include highly generic terms like 'software-and-data' and broad API-related phrases without scope constraints, which increases accidental or adversarial activation. An attacker or ordinary user could easily invoke this skill in contexts where it is not the best fit, causing misrouting and reducing the reliability of downstream safety and quality controls.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains a very broad activation phrase covering generic topics like software, data, OpenAPI, Swagger, API documentation, REST APIs, workflows, artifacts, checklists, analysis, and implementation support. This increases the chance the skill is invoked for ordinary requests the user did not explicitly intend, which can cause prompt-routing confusion, unnecessary exposure of tool behavior, or unintended handling of unrelated tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the agent to route into this skill based on loose semantic overlap rather than explicit user consent. In this skill, the broad documentation and software-related scope compounds the risk, making unintended invocation more likely and potentially causing the system to apply the wrong workflow or disclose irrelevant internal behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are overly broad and can match ordinary user phrasing, causing the skill to activate outside its intended scope. That increases the chance of unintended routing, prompt interference, or accidental invocation in unrelated conversations, which is a genuine security and reliability risk for agent behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.