Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable OpenAPI/Swagger documentation helper, with only routing-quality issues in its trigger wording.

Installers should treat this as a documentation-assistance skill for explicit OpenAPI, Swagger, REST API schema, or API documentation tasks. The publisher should narrow and repair the trigger examples to reduce accidental activation, especially because implicit invocation is enabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are extremely generic and repetitive, causing the skill to match on broad OpenAPI or workflow-related requests rather than clearly scoped intents. This can lead to unintended activation, where the agent applies this skill in contexts it was not meant for, increasing the chance of irrelevant guidance, prompt collision with other skills, or unsafe handling of adjacent tasks.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and can activate the skill for generic requests about software, APIs, or workflows without clear scoping. In an agent system, over-broad activation can cause the wrong skill to run, increasing the chance of unintended prompt injection exposure, incorrect task routing, or generation of inappropriate artifacts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to match many normal API or software requests, which can cause unintended invocation of this skill outside its intended scope. Overbroad activation increases the chance that unrelated user input is routed through instructions or workflows that are not appropriate for the task, reducing reliability and potentially enabling misuse through prompt steering.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are malformed, truncated, and overly generic, so they do not provide reliable guidance for correct activation. Poor trigger examples can cause accidental invocation or inconsistent routing behavior, especially in systems that depend on example phrases to disambiguate similar skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation description is very broad, combining multiple generic domains and task types without clear boundaries. This can cause the skill to trigger on loosely related requests, leading to incorrect routing, unexpected behavior, or the skill taking over tasks better handled by a different, more appropriate skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are highly generic and resemble normal user language, which increases the chance of unintended invocation during unrelated conversations. Overbroad sample triggers can train or bias routing systems toward activating this skill too often, reducing reliability and potentially exposing users to irrelevant or misleading outputs.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while using a very broad default prompt and a generic description, which can cause the agent to trigger this skill in unintended contexts. That creates an unnecessary expansion of the skill’s execution surface and may lead to prompt-routing mistakes, unintended data exposure to the skill, or user actions being influenced by the wrong capability.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is overly broad and can match ordinary user phrasing, which increases the chance that this skill is invoked when a user did not explicitly request OpenAPI or Swagger help. In an agent-routing context, broad triggers can cause inappropriate skill activation, mis-handle user intent, and route unrelated inputs into a workflow that may generate misleading or irrelevant outputs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger descriptions and example sentences lack clear scope, boundaries, and disambiguation rules, making it difficult for the agent to distinguish this skill from many general software-assistance requests. This ambiguity can lead to false activations, prompt-routing errors, and reduced reliability of downstream behavior, especially because the skill is framed as broadly applicable to workflows, artifacts, and analysis.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.