Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work and does not include code, persistence, credential handling, or hidden execution behavior.

Installers should be aware that this skill may activate on broad API-adjacent wording. It is best used when the user explicitly asks for OpenAPI, Swagger, REST API documentation, validation, or improvement help.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, repetitive, and include generic wording such as 'Help me' and 'I need a practical workflow,' which increases the chance the skill is invoked outside the author's intended scope. In an agent system, ambiguous activation can route unrelated user requests into this skill, causing incorrect assistance, context confusion, or unsafe delegation to the wrong workflow.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, templated, and partially malformed, which increases the chance that the skill is invoked in contexts the user did not clearly intend. In an agent environment, unintended invocation can route user data or decision flow into the wrong skill, causing confusing outputs, workflow hijacking, or misuse of downstream tooling.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description and usage condition are broad enough that it may activate for loosely related software or API-documentation requests, causing the agent to invoke this skill outside its intended scope. Over-broad triggering is dangerous because it can override more appropriate skills or lead the agent to generate documentation-oriented outputs when the user actually needs different, potentially more sensitive assistance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes broad terms such as 'software-and-data' and 'developer experience' without constraints or exclusion rules, which makes accidental activation likely. In a multi-skill environment, this increases the chance of misrouting requests, producing irrelevant outputs, and potentially exposing user context to an unnecessary skill path.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases are generic and partially malformed, so they do not meaningfully constrain activation behavior or help downstream systems distinguish valid from invalid use cases. Poor trigger examples can normalize ambiguous matching and make the skill fire on vague requests that only superficially resemble the intended domain.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation but does not define narrow activation constraints, increasing the chance it is triggered during ordinary conversation or loosely related requests. Because this skill can shape outputs around API documentation tasks, over-broad activation can cause unintended routing, prompt-scope expansion, or opportunistic invocation by adversarial user phrasing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses broad, natural phrasing such as 'help me' and general backend/platform language, which can overlap with common user requests unrelated to this specific skill. This increases the likelihood of accidental invocation and makes prompt-trigger boundaries easier to manipulate, especially when combined with implicit invocation.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is so generic that ordinary user requests could activate the skill unintentionally, causing over-broad routing and prompt-scope confusion. In an agent system, ambiguous activation increases the chance that this skill handles requests outside its intended boundary, which can amplify downstream prompt injection or unsafe task execution risks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text does not clearly define when the skill should and should not be used, so the orchestration layer may invoke it for loosely related documentation or backend questions. This weak scoping can lead to inappropriate tool selection, mishandling of user intent, and increased exposure to adversarial content routed through the wrong skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.