Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a plain documentation-helper skill for OpenAPI/Swagger work, with broad activation wording but no hidden execution, credential use, persistence, or destructive behavior.

Before installing, be aware this skill may activate for broad API or documentation requests because its triggers are loose. It appears safe for OpenAPI/Swagger documentation assistance, but users who want tighter routing should narrow the trigger phrases or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are generic and loosely scoped, which increases the chance that the skill is invoked for broad software or API-related requests outside its intended purpose. In an agent ecosystem, unintended invocation can cause context confusion, inappropriate tool selection, or execution of the wrong workflow, especially when trigger matching is automated or keyword-driven.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, repetitive, and partially templated, which increases the chance that ordinary user requests about APIs or documentation could activate the skill unintentionally. In an agent environment, overbroad activation can cause the wrong workflow to run, leading to irrelevant actions, confusion, or unsafe context switching if the skill influences downstream behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to activate on generic API-related requests, not just narrowly on OpenAPI/Swagger documentation generation and validation. Over-broad routing can cause the wrong skill to handle user requests, increasing the chance of inappropriate file access, irrelevant instructions, or unsafe automation in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger keywords include very generic terms like "openapi," "swagger," "api documentation," and "rest api" without scope guards, so the skill may be selected for many unrelated developer requests. In an agentic system, ambiguous triggers can misroute tasks and expand the skill's operational surface, making downstream mistakes or unsafe actions more likely.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to match many ordinary API or software discussions, which can cause the skill to activate outside its intended scope. Over-broad triggering can lead to inappropriate delegation, context leakage into the skill workflow, or user confusion when the agent applies specialized guidance where it was not requested.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list contains common technical terms like 'openapi', 'swagger', 'api documentation', and 'rest api' without qualifiers, making accidental activation likely in routine engineering conversations. In agent systems, this increases the chance of misrouting requests and exposing unrelated user context to a skill that was not actually needed.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest allows implicit invocation and pairs it with a very broad default prompt covering common API, software, and documentation requests. This can cause the skill to be auto-selected in situations beyond the user's explicit intent, increasing the chance of unintended prompt injection exposure, over-broad data handling, or unauthorized action within agent workflows.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me'), which can cause the skill to activate for requests far outside its intended OpenAPI/Swagger scope. In an agent environment, overly broad activation increases the chance of unintended routing, confusing responses, and misuse of the skill on unrelated tasks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This trigger sentence is too ambiguous to reliably constrain invocation to the documented skill purpose, making accidental or incorrect activation more likely. Ambiguous routing conditions can degrade trust and may expose the skill to inputs it was not designed to handle, especially in automated orchestration contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.