Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation helper for OpenAPI and Swagger work, with broad activation wording but no hidden, privileged, persistent, or destructive behavior.

This skill is reasonable to install if you want help with OpenAPI or Swagger documentation. Because its activation wording is broad, review when it is invoked and check any suggested code or documentation changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad and partly templated, which can cause the skill to activate in situations where a user only casually mentions OpenAPI, Swagger, or API documentation. Overbroad activation is dangerous because it can lead to unintended routing, irrelevant instruction injection into unrelated tasks, and increased attack surface for prompt-confusion or skill misuse.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and templated enough that the skill may activate for loosely related user requests, causing unintended routing or over-invocation. In an agent system, ambiguous activation increases the chance that untrusted or irrelevant inputs are handled by this skill, which can lead to incorrect assistance, prompt-surface expansion, or abuse of downstream workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is scoped to a broad topic area and includes generic phrasing like helping with software-and-data, OpenAPI, Swagger, API documentation, and REST APIs without strong boundaries on when the skill should or should not activate. In an agentic system, overly broad routing criteria can cause inappropriate invocation on loosely related requests, increasing the chance of irrelevant actions, unintended data handling, or policy bypass through misrouting.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include generic terms such as 'software-and-data' and 'developer experience' that are not specific enough to OpenAPI documentation work. Generic trigger terms increase false-positive activation and can cause the skill to intercept unrelated requests, which is dangerous in systems where skill routing influences what instructions or capabilities are applied.

Vague Triggers

Low
Confidence
83% confidence
Finding
The example trigger sentences are malformed and truncated, which makes invocation boundaries ambiguous and reduces the reliability of safe routing behavior. While less severe than broad keywords, unclear examples can still train or bias users and orchestration systems toward accidental invocation in cases that were not intended.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad and loosely bounded, combining many generic topics like software-and-data, OpenAPI, Swagger, API documentation, and REST API without clear exclusions or routing criteria. This can cause the skill to activate on ordinary engineering requests that do not actually need this specialized workflow, increasing the chance of misrouting, irrelevant guidance, or unintended interception of user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list is ambiguous because it consists of broad industry terms with no scope constraints, qualifiers, or negative cases. A router or agent relying on these terms may spuriously invoke this skill for many unrelated requests, degrading precision and potentially suppressing more appropriate skills or default handling.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger phrases use generic openings like 'Help me' and 'I need a practical workflow', which overlap heavily with normal user language across many domains. Because the examples are not specific to a narrow OpenAPI documentation task, they can train or bias invocation toward overbroad matching and accidental activation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation while providing no narrowly scoped trigger rules beyond a broad description and default prompt. This can cause the agent to auto-select the skill for ordinary API or documentation conversations, expanding its activation surface and increasing the chance of unintended prompt/context exposure or inappropriate tool use.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt uses very broad natural-language phrasing about helping backend and platform teams with generating, improving, and validating API documentation. Because this overlaps with many routine software requests, it can spuriously match unrelated conversations and trigger the skill in contexts the user did not intend, especially when implicit invocation is enabled.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are malformed, generic, and broad enough that unrelated user requests containing common OpenAPI or workflow language could invoke the skill unintentionally. Unintended invocation can route users into the wrong workflow, causing context confusion, incorrect outputs, or bypass of more appropriate skills, which is a security and reliability concern in agent routing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.