Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a simple OpenAPI documentation helper skill with overly broad activation wording, but no evidence of hidden execution, data theft, persistence, or destructive behavior.

Before installing, understand that this skill may activate on broad API-related phrasing, not only explicit OpenAPI or Swagger documentation requests. It appears safe as a documentation helper, but publishers should narrow the trigger wording or require clearer intent to reduce accidental invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are broad, repetitive, and weakly scoped, which can cause the skill to activate for loosely related requests rather than explicit user intent. In an agent system, ambiguous invocation expands the skill’s execution surface and can lead to incorrect routing, irrelevant automation, or unintended handling of user prompts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, repetitive, and partially malformed, which can cause the skill to activate for loosely related requests rather than explicit intent. In an agent system, overbroad activation increases the chance of prompt-routing mistakes, unintended disclosure of internal skill behavior, or inappropriate execution in contexts the user did not mean to invoke.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and usage guidance are broad enough that the skill may activate for loosely related requests, causing inappropriate routing or overuse outside its intended scope. In an agent system, ambiguous activation conditions can lead to capability confusion, where the model applies this skill to generic software tasks and produces irrelevant or misleading outputs.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword triggers include broad phrases like 'software-and-data' and 'rest api' that commonly appear in many unrelated engineering requests. This increases the chance of accidental invocation, which can degrade agent reliability and potentially expose users to workflows or assumptions that do not fit their task.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description includes broad, high-frequency trigger terms such as "software-and-data," "openapi," "swagger," and "rest api" without clear exclusion criteria or tighter contextual guards. This can cause the skill to activate for loosely related requests, leading to unintended routing, over-collection of context, or inappropriate automation in conversations that only partially match the intended use case.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword-based trigger section is overly permissive and lacks negative examples or contextual constraints, so ordinary developer-experience or REST API discussions may invoke this skill even when documentation generation is not the user's goal. In an agent setting, this increases the chance of misrouting and can bias downstream behavior toward producing or modifying artifacts the user did not request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation while using a very broad description and default prompt that match common API/help-seeking requests. This can cause the agent to invoke the skill in situations the user did not clearly request, increasing the chance of unintended prompt injection exposure, misrouting, or unauthorized use of the skill’s behavior.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is overly broad and can match ordinary user phrasing rather than a clear, deliberate invocation of this skill. That creates unintended activation risk, causing the agent to route unrelated requests into this skill and potentially override more appropriate handling or expose users to irrelevant generated workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger phrase is ambiguous and does not define clear activation boundaries, so the skill may be selected when the user's intent is only partially related or entirely different. In an agentic system, ambiguous routing increases the chance of prompt/skill mis-selection, reducing reliability and creating opportunities for unintended behavior propagation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.