Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a simple OpenAPI/Swagger documentation helper with broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

This skill is reasonable to install for OpenAPI or Swagger documentation work. Be aware that its broad trigger phrases could cause it to activate for generic API or developer-experience requests; explicit invocation or tighter routing would reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic and loosely scoped, so the skill may activate on broad requests that merely mention backend, OpenAPI, or practical workflow language. Unintended invocation can cause the agent to apply this skill in the wrong context, leading to irrelevant actions, prompt hijacking exposure through mismatched contexts, or suppression of a more appropriate and safer skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic and expansive enough to activate the skill for broad software, API, or documentation requests without clear scoping. This can cause unintended routing or over-invocation of the skill, which is risky in agent systems because the wrong workflow may be applied to unrelated user tasks and may crowd out safer or more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description and usage guidance are broad enough to match many generic software or API-related requests, which can cause inappropriate auto-selection of this skill outside its intended OpenAPI documentation scope. Over-broad routing increases the chance that unrelated user input is handled with the wrong workflow, potentially causing data leakage into the skill context, degraded guidance, or unsafe assumptions in downstream agent behavior.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list contains generic triggers such as 'software-and-data' and 'developer experience' that are not specific to OpenAPI documentation generation. In agentic routing systems, these loose triggers can cause excessive or mistaken activation, expanding the skill's effective authority and increasing the likelihood of misrouting or unintended processing of user requests.

Vague Triggers

Low
Confidence
85% confidence
Finding
The malformed example trigger sentences do not establish a clear invocation boundary, making it harder for developers or routing logic to understand exactly when this skill should activate. Ambiguity in trigger examples can contribute to accidental invocation or inconsistent behavior, though the impact is lower than the broad description and keyword issues because examples are usually secondary to explicit trigger rules.

Vague Triggers

Medium
Confidence
92% confidence
Finding
技能描述中的触发条件覆盖了较宽的主题范围,如 software-and-data、openapi、swagger、api documentation、rest api,且没有给出明确排除条件或边界。这会增加被非目标请求误触发的概率,导致代理在不合适的上下文中调用该技能,带来错误建议、越权处理无关任务或扩大攻击面。

Vague Triggers

Medium
Confidence
95% confidence
Finding
关键词列表包含较通用术语,如 software-and-data、rest api、developer experience,若缺少上下文约束,容易匹配到大量并非 OpenAPI 文档场景的请求。这类误触发通常不是直接安全漏洞,但会让技能在不相关任务中介入,增加提示注入承载面、错误自动化决策和输出不当内容的风险。

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt contains a broad natural-language trigger phrase that can cause the skill to be invoked in situations only loosely related to OpenAPI documentation. Overbroad invocation increases the chance of unintended routing, prompt-surface expansion, and accidental handling of user requests outside the intended scope, which can degrade security boundaries between skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence begins with a broad everyday phrase ('Help me ...'), which can cause the skill to activate on many unrelated requests that merely contain generic help-seeking language. Over-broad activation increases the chance of unintended routing, where users may receive this skill in contexts it was not designed for, reducing trust and potentially causing inappropriate handling of prompts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is ambiguous because it frames activation around a vague request for 'a practical workflow' without clearly constraining the scope to OpenAPI/Swagger documentation tasks. This ambiguity can make the skill fire for broad engineering-process requests that are unrelated to API specs, leading to accidental invocation and misclassification of user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.