Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work and does not contain executable code, hidden data handling, persistence, or privileged behavior.

Installers should understand that this skill may be invoked for broad API or developer-experience prompts, so it is best used when the user explicitly wants OpenAPI/Swagger documentation help. No hidden execution or sensitive access was found.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely generic and partly templated, so the skill may activate on broad software or API-help requests that were not intended to invoke this specific capability. In an agent environment, ambiguous routing can cause the wrong skill to handle user input, leading to misleading outputs, inappropriate actions, or accidental disclosure of context to an unnecessary subsystem.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and partially generic, which can cause the skill to activate in contexts beyond the author's intended OpenAPI-documentation use case. Unintended invocation increases the chance that the agent applies this workflow to unrelated requests, causing prompt-routing errors, confusing outputs, or accidental exposure of internal process assumptions in mixed-skill environments.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is broad enough to match many routine API- or software-related requests without clearly delimiting when this skill should and should not activate. Over-broad activation can cause incorrect routing, unnecessary invocation of the skill, and increased exposure to prompt-cross contamination from unrelated contexts.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger keywords include broad technical phrases like 'software-and-data' and 'rest api' that commonly appear in unrelated requests. This increases the chance of accidental activation, which can misroute user requests and make downstream behavior less predictable or policy-safe.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger sentences are generic and only show positive activation examples, without clarifying borderline or non-trigger cases. This can reinforce over-activation behavior and make it harder for an orchestrator or reviewer to distinguish intended use from incidental keyword matches.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are overly broad and include generic terms like “software-and-data,” “rest api,” and “developer experience,” which can match many unrelated conversations. This can cause the skill to activate outside its intended scope, leading to inappropriate guidance, prompt hijacking surface expansion, or accidental disclosure/misapplication of workflow instructions in unrelated contexts.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The usage description says to use the skill whenever the user mentions certain topics or needs practical workflows, artifacts, checklists, analysis, or implementation support, but it does not clearly constrain what qualifies as in-scope. This ambiguity increases the chance of over-invocation, making the skill easier to trigger in loosely related requests and broadening the attack surface for unintended behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default_prompt is extremely broad and generic, making it easy for the skill to be invoked in situations that only loosely relate to OpenAPI or API documentation. Overbroad invocation text can cause unintended routing, leading users to receive this skill's guidance in contexts where it is not appropriate and potentially exposing downstream systems to prompt confusion or misuse.

Vague Triggers

Medium
Confidence
95% confidence
Finding
allow_implicit_invocation: true permits automatic activation without sufficiently narrow criteria, which increases the chance of accidental or inappropriate invocation. In a multi-skill environment, this can cause the skill to intercept unrelated requests, creating prompt-routing errors, reduced reliability, and opportunities for policy bypass through ambiguous phrasing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence begins with a generic everyday phrase ('Help me') and then appends a long requirement description, making activation criteria broad and imprecise. This can cause the skill to trigger for unrelated user requests, increasing the chance that the agent routes conversations into this skill unexpectedly and exposes users to irrelevant or misleading workflow guidance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The sentence 'I need a practical workflow for ...' is still too abstract and does not uniquely identify a concrete OpenAPI/Swagger documentation task. Ambiguous triggers weaken skill routing boundaries, so normal planning or workflow requests that are only loosely related may invoke this skill when another tool or no tool would be more appropriate.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.