Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation workflow helper for OpenAPI/Swagger tasks, with some broad and malformed trigger text but no harmful execution, persistence, or data-handling behavior in the artifacts.

Installers should be aware that the skill may activate on broad API/software-documentation phrasing; use it for OpenAPI, Swagger, REST endpoint documentation, schema review, and validation tasks, and avoid relying on it for unrelated backend work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are generic and malformed enough that they could match loosely related user requests and invoke the skill when the user did not explicitly ask for it. In an agent system, overbroad invocation increases the chance of unintended prompt injection exposure, irrelevant execution paths, or disclosure/manipulation through the wrong skill being selected.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and partially templated, which can cause the skill to activate for loosely related requests rather than explicit OpenAPI documentation tasks. In an agent environment, overbroad activation can route user inputs into an unintended workflow, increasing the chance of inappropriate context handling, misleading outputs, or accidental invocation on unrelated developer requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description contains very broad activation cues such as general software-and-data and API documentation terms, which can cause the skill to trigger on many loosely related requests. Overbroad routing is dangerous because it can divert user requests to the wrong skill, increasing the chance of irrelevant guidance, context leakage across tasks, or bypass of more appropriate specialized safeguards.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger examples use broad everyday phrasing and malformed sentences that do not clearly constrain activation to legitimate OpenAPI documentation requests. This makes accidental or inappropriate invocation more likely, which can degrade routing accuracy and expose users to off-target behavior in contexts where another skill should have handled the request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while providing only a broad, generic description of when it should activate. This can cause the agent to invoke the skill in contexts the user did not clearly intend, increasing the chance of prompt-scope confusion, unintended data exposure to the skill, or unsafe automation triggered by loosely related requests.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), which can cause the skill to activate in situations far beyond OpenAPI documentation work. Over-broad activation increases the chance of unintended routing, causing unrelated user requests to be handled by this skill and potentially producing irrelevant or unsafe guidance under the wrong context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is too generic and does not clearly define the conditions under which the skill should activate. Ambiguous invocation logic can lead to accidental selection for loosely related 'practical workflow' requests, reducing routing integrity and increasing the risk of context-inappropriate outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.