Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk OpenAPI documentation helper with overly broad activation wording but no executable code, persistence, credential handling, or hidden data flow.

Installers should expect a documentation-assistance skill for OpenAPI/Swagger work. Consider tightening or disabling implicit invocation if accidental activation on general backend or developer-experience requests would be disruptive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad, malformed, and effectively allow the skill to activate for vague requests rather than clearly scoped OpenAPI documentation tasks. In an agent system, ambiguous activation criteria can cause inappropriate routing, unexpected invocation, or prompt-context contamination from unrelated user requests, which may degrade safety and reliability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and partly templated in a way that could cause the skill to activate on loosely related requests rather than an explicit user choice. In an agent environment, unintended invocation can route user data or workflow control into the wrong skill, causing confusion, incorrect outputs, or unsafe downstream actions if later versions of the skill gain more capabilities.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and usage guidance are broad enough that the skill may activate for loosely related requests, causing it to steer conversations into OpenAPI or REST documentation workflows when that was not the user's intent. In an agent system, ambiguous routing can produce incorrect tool/skill selection, increasing the chance of irrelevant actions, bad guidance, or accidental exposure of context to an unnecessary skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrases are malformed, truncated, and too vague to establish reliable invocation boundaries, which makes accidental or inconsistent activation more likely. Poor trigger examples can also train downstream routing behavior incorrectly, leading the agent to invoke this skill for unrelated developer requests.

Vague Triggers

Medium
Confidence
94% confidence
Finding
触发关键词包含“software-and-data”“developer experience”等非常宽泛的术语,且未提供明确排除条件,容易让编排器在与 OpenAPI 无关的场景中误选该技能。误触发本身不一定直接造成安全破坏,但会扩大技能适用面,增加不相关上下文被处理、错误建议被输出或与其他技能竞争的风险。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述声明在用户提到 software-and-data、openapi、swagger、api documentation、rest api 时均可使用,但缺少清晰边界和不适用情形,导致路由范围过宽。这样的定义会让系统在需求尚未明确为 API 文档工作时也调用该技能,从而带来误导性输出、资源浪费和潜在的数据最小化问题。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation with no visible trigger constraints, which increases the chance that the agent will activate this skill from ordinary conversation that merely mentions APIs, Swagger, or documentation. This can cause unintended routing, context leakage into the skill, or user confusion about which capability is being used, especially because the skill scope is broad and overlaps with common engineering discussions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses broad natural-language phrasing such as 'help me' and general backend/platform needs, which can overlap with many normal user requests and make accidental invocation more likely. When combined with implicit invocation, this broad phrasing materially increases the attack surface for prompt/skill hijacking and misrouting by letting routine technical conversation satisfy activation heuristics.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence begins with a highly generic phrase ('Help me ...') that overlaps with normal user language and can cause the skill to activate unintentionally. In an agent environment, overly broad invocation patterns increase the chance of misrouting requests, causing the wrong skill to handle user input and potentially exposing unrelated context or producing unsafe actions under incorrect assumptions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence uses a broad request template ('I need a practical workflow for ...') without enough domain constraints, making accidental invocation plausible across many unrelated tasks. This weak specificity can lead to inappropriate tool selection, confusing outputs, and increased attack surface for prompt-routing abuse where an attacker intentionally phrases a request to activate this skill outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.