Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work, with no executable code or hidden data access found.

Safe to install for OpenAPI or Swagger documentation help. Be aware it may be invoked for some broad API-related requests, so users should confirm the task is actually about API documentation if the skill appears unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad, templated, and not tightly scoped to specific user intent, which can cause the skill to activate for loosely related requests. In an agent environment, overbroad activation increases the chance of inappropriate tool or workflow selection, leading to confusing outputs, accidental disclosure of irrelevant context, or bypass of better-suited safeguards in other skills.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and partially templated in a way that could cause the skill to activate for loosely related requests rather than explicit user intent. In an agent environment, over-broad invocation increases the chance of unintended routing, causing the model to apply this skill in the wrong context and potentially generate misleading API documentation guidance or override a more appropriate skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and 'Use when' clause cast a very wide net across generic terms like software-and-data, openapi, swagger, api documentation, and rest api, plus broad task types like workflow, checklist, analysis, or implementation support. This can cause the skill to activate in situations outside its narrow intended scope, leading to inappropriate routing, overreach into unrelated tasks, or accidental application of the skill to sensitive API content without sufficient gating.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are broad, high-frequency terms that commonly appear in benign engineering conversations, especially 'openapi', 'swagger', and 'developer experience'. Without stronger qualifiers, these terms can spuriously invoke the skill and bias responses toward this workflow even when the user did not request documentation generation or validation.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger sentences are malformed, truncated, and generic, which makes them poor boundaries for safe activation and increases ambiguity about when the skill should run. Ambiguous examples can train or encourage overly permissive matching behavior, compounding the broad-trigger problem elsewhere in the file.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and usage conditions are broad enough that the agent may invoke this skill for loosely related requests, not just concrete OpenAPI documentation tasks. Over-broad activation can cause context hijacking, incorrect tool/skill routing, and unintended handling of user requests under the wrong operational policy.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list includes very common and high-level terms such as openapi, swagger, api documentation, and rest api without qualifiers, which increases the chance of accidental activation across many unrelated conversations. In an agent environment, this can lead to unnecessary skill invocation, prompt-scope confusion, and possible interference with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without any visible constrained activation criteria, which increases the chance the agent will trigger this skill on loosely related user requests. Because the skill description and prompt are broad, this can cause over-routing, unintended tool use, and create an attack surface for prompt steering or capability misuse in contexts where the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses broad, everyday phrasing such as 'help me' and general backend/platform wording, which can overlap with many normal software requests beyond OpenAPI documentation. In combination with implicit invocation, this makes accidental activation more likely and can cause the model to apply this skill when it is not the best or safest match for the user's intent.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger sentence is so generic that normal user phrasing could activate the skill unintentionally, causing prompt routing to select this skill when the user did not explicitly request it. In an agent system, over-broad activation increases the chance of irrelevant instructions being injected into the conversation flow and can displace safer or more appropriate skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
This trigger lacks clear activation boundaries and could match a wide range of vague requests, making skill selection unpredictable. Ambiguous routing is dangerous because it can expose users to incorrect workflows, unintended tool use, or context leakage from a skill that was not actually needed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.