Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a simple OpenAPI documentation workflow skill with overly broad triggers, but it does not install code, request credentials, persist, or perform hidden actions.

Install only if you want an agent to help with OpenAPI, Swagger, or REST API documentation tasks. Be aware it may activate on some general API or developer-experience requests because the trigger wording is broad; review outputs as normal technical documentation guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The requirement plan claims validated demand for OpenAPI/Swagger documentation, but much of the cited evidence appears unrelated or only weakly related to that claim. This can mislead routing, prioritization, or approval decisions by presenting unsupported justification as established demand, reducing trust in the skill-selection process.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad, repetitive, and include generic phrases that could match loosely related user requests, increasing the chance the skill is invoked when the user did not specifically ask for OpenAPI documentation help. In an agent ecosystem, unintended invocation can cause context switching, irrelevant actions, or downstream execution of the wrong workflow, which is a real prompt-routing and scope-control weakness even if not directly code-execution related.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed trigger phrases are very broad and partly templated, making it easy for unrelated user requests containing generic terms like 'workflow', 'OpenAPI', or 'REST API' to activate the skill unintentionally. In an agent environment, overbroad activation can route conversations to the wrong skill, causing inappropriate handling, confusion, or unsafe downstream actions if the skill has privileged capabilities.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and usage guidance are broad enough that an agent may invoke this skill for loosely related requests, increasing the chance of misrouting or over-activation. In an agent system, ambiguous activation can cause unintended context capture, irrelevant instructions to be applied, or user requests to be steered into the wrong workflow.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include very generic terms such as 'software-and-data' and 'developer experience' that are not sufficiently specific to OpenAPI documentation tasks. These broad keywords can cause accidental invocation in unrelated conversations, which may degrade agent reliability and create opportunities for prompt-routing abuse.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases use broad natural-language patterns like 'Help me' and 'I need a practical workflow' with only weak scope anchoring, which can train or encourage overly permissive matching behavior. While the examples are somewhat tied to OpenAPI documentation, their phrasing still risks false activations from partially matching everyday requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description is broad enough that the skill may trigger for generic software or API-related requests that do not actually require OpenAPI documentation support. In an agent system, overly broad routing can cause the wrong skill to handle user input, leading to irrelevant guidance, reduced reliability, or accidental exposure of contextual data to a skill that did not need it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list contains broad terms like 'software-and-data' and 'developer experience' without constraints, which can cause spurious activation across many unrelated requests. This weakens skill isolation and increases the chance of incorrect tool routing, which is a security and safety concern in agentic systems because capabilities may be invoked outside their intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation but does not define clear trigger constraints or narrow invocation conditions. This can cause the agent to activate the skill in broader contexts than intended, increasing the chance of inappropriate use, prompt-scope expansion, or adversarial routing into a capability the user did not explicitly request.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger phrase beginning with 'Help me' is so broad that it can activate on ordinary user language with little connection to OpenAPI or API documentation. Overbroad activation can cause incorrect skill routing, unintended prompt injection surface expansion, and user confusion because the skill may engage outside its intended scope.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The remaining trigger phrases are ambiguous and describe the requirement text itself rather than clear user intents, so they do not provide reliable scope boundaries for activation. In a skill-routing system, vague triggers increase accidental invocation and make it easier for unrelated prompts to be classified into this skill incorrectly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.