Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a static OpenAPI documentation helper with some overly broad activation wording but no hidden execution, credential handling, persistence, or data movement.

Installers should be aware that the skill may activate on broad API-documentation wording; use it for explicit OpenAPI, Swagger, REST API spec generation, validation, or documentation tasks, and prefer tighter trigger wording if precise routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are extremely broad and partly malformed, making accidental or inappropriate invocation more likely when a user mentions common API-documentation topics. In an agent ecosystem, ambiguous activation can route unrelated requests into this skill, causing confusing behavior, overcollection of context, or unintended processing without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are so broad and templated that the skill may activate for loosely related requests, causing unintended routing or invocation. In an agent ecosystem, overly permissive activation can expose users to irrelevant automation, increase prompt-surface for instruction collisions, and make it easier for adversarial phrasing to invoke the skill outside its intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match a wide range of common software requests, which can cause the agent to invoke this skill outside its intended scope. Over-broad activation increases the chance of prompt-routing errors, where this skill may override or interfere with more appropriate skills and expose users to incorrect guidance or unintended processing of sensitive API-related inputs.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases use generic language like 'Help me' and 'I need a practical workflow' with minimal scoping, which can train or bias the routing system toward activating this skill on loosely related requests. This creates a misrouting risk that can degrade reliability and cause the agent to apply OpenAPI-documentation behavior to unrelated tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description is broad and loosely bounded, covering generic software and API-documentation terms that commonly appear in normal conversation. This can cause the skill to trigger outside its intended scope, leading to incorrect routing, unintended instruction injection into unrelated tasks, or overshadowing a more appropriate skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases begin with very common helper language like 'Help me' and 'I need', while lacking negative examples or disambiguation rules. In practice, this increases accidental invocation risk because ordinary user phrasing may match the skill even when the user is not asking for OpenAPI-specific assistance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is written as a broad natural-language invocation that could cause the skill to trigger in loosely related conversations without strong scoping. Because implicit invocation is enabled, this increases the chance of unintended activation, context leakage into the skill, or confusing agent behavior when users discuss APIs or documentation incidentally.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing and cause this skill to activate in situations beyond its intended scope. Over-broad activation increases the chance of misrouting requests, causing the agent to apply specialized OpenAPI guidance when the user did not explicitly ask for it, which can degrade reliability and create prompt-injection exposure through unnecessary skill invocation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.