Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation helper for OpenAPI/Swagger work, with broad trigger wording but no executable code, persistence, credential handling, or hidden behavior.

Install this skill if you want help with OpenAPI or Swagger documentation. Be aware that its implicit trigger wording is loose; if your environment allows it, prefer explicit invocation or tighten triggers so general API/backend questions do not route to this skill unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are generic and template-like, making it easier for unrelated user requests to accidentally match and invoke this skill. In a documentation-generation context, unintended invocation can cause the agent to apply the wrong workflow, produce irrelevant artifacts, or expose broader capabilities than the user intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are so generic that they can activate on ordinary user requests and cause the skill to run outside its intended scope. Over-broad activation increases the chance of unintended prompt/context injection into unrelated conversations and can lead to inappropriate handling of user tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description and activation guidance are broad enough that the skill may trigger in many API-related conversations where the user did not intend to invoke it. Over-broad activation can cause inappropriate context injection, reduce answer quality, and create opportunities for prompt-scope confusion across unrelated tasks.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The listed keywords include very broad terms like 'software-and-data', 'rest api', and 'developer experience', which can match a large number of unrelated conversations. This increases the chance of accidental invocation and unintended instruction precedence, which can interfere with safer or more relevant skills.

Vague Triggers

Low
Confidence
89% confidence
Finding
Malformed example triggers weaken activation reliability and make it unclear when the skill should or should not fire. While not directly exploitable like code execution, ambiguous examples contribute to misrouting and inconsistent behavior, which is a security-relevant prompt-selection weakness.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description and use conditions are broad enough that the skill may be invoked for loosely related API or software topics instead of narrowly scoped OpenAPI/Swagger documentation tasks. Over-broad routing can cause incorrect delegation, irrelevant outputs, or unintended exposure of user context to a skill that was not the best match, which is a real security and safety boundary issue in agent systems.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The keyword list includes highly generic terms like "software-and-data" and broad API-related phrases without contextual constraints. In a skill-routing environment, this increases the chance of accidental invocation on unrelated requests, which can mis-handle user intent and expand the skill's effective authority beyond its intended purpose.

Vague Triggers

Low
Confidence
77% confidence
Finding
The example trigger phrases are broad and only demonstrate positive matches, without showing boundary cases or disallowed invocations. This makes the routing surface ambiguous and can encourage over-triggering, especially when examples are reused by matching heuristics or downstream tooling as implicit routing guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase that overlaps with ordinary user requests about backend, platform, API, OpenAPI, Swagger, and REST documentation. Combined with implicit invocation, this can cause the skill to activate unexpectedly in benign conversations, increasing the chance of prompt injection exposure, unintended tool use, or undesired routing of sensitive user content into the skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentence begins with the generic phrase "Help me," which is broad enough to match many unrelated user requests and can cause unintended activation of this skill. In a routing or orchestration system, overly broad triggers increase the chance that the skill handles prompts outside its intended scope, leading to confusion, irrelevant outputs, or unsafe delegation chains.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is vague about when the skill should activate and does not clearly bind activation to OpenAPI, Swagger, or REST API documentation work. Ambiguous activation criteria can cause misrouting, where the skill is invoked for adjacent but unintended tasks, reducing reliability and potentially exposing downstream tools or workflows to irrelevant inputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.