Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable OpenAPI documentation helper with broad activation wording but no hidden or destructive behavior.

Installers should be aware that this skill may be invoked broadly around OpenAPI, Swagger, REST APIs, or API documentation. It appears safe for documentation assistance, but users may want to tighten trigger phrasing if they only want explicit OpenAPI generation or validation requests to use it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentences are broad and effectively allow the skill to activate on vague references to software, OpenAPI, Swagger, or REST API documentation without clear scoping. In an agentic system, this can cause inappropriate invocation, context overreach, or unintended takeover of requests that only partially match, increasing the chance of unsafe or misleading automation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and partially templated, which increases the chance the skill is invoked in contexts the user did not clearly intend. In an agent environment, unintended invocation can cause the model to follow the wrong workflow, override a more appropriate skill, or process unrelated API material in ways that degrade safety and reliability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description says to use this skill when a user asks for broad topics like "software-and-data," "openapi," "swagger," or "rest api," which are common terms in many unrelated conversations. Overbroad activation criteria can cause the skill to trigger outside its intended scope, leading to inappropriate context injection or unnecessary execution of workflow instructions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include generic technical phrases such as "software-and-data," "openapi," "swagger," "api documentation," and "rest api," which can appear in ordinary discussion without any request to invoke the skill. This increases the chance of accidental or adversarial triggering, which may misroute the agent or override a more appropriate capability.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger sentences are malformed and truncated, so they do not provide reliable invocation patterns for the agent or maintainers. Ambiguous examples can cause inconsistent routing behavior and make it easier for loosely related prompts to match unintentionally.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description defines the skill in very broad terms and ties activation to a wide class of user requests around OpenAPI, Swagger, API documentation, and implementation support. This can cause the skill to be invoked in contexts where the user did not specifically request this capability, increasing the chance of unintended prompt injection exposure, wrong-tool execution, or irrelevant output.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list is short, generic, and lacks scope constraints, so common terms like 'openapi', 'swagger', or 'rest api' may trigger the skill even when documentation generation is not the user's goal. Overbroad keyword routing can misapply the skill, which is a security-relevant reliability issue because adversarial or unrelated inputs may reach privileged or specialized workflows unexpectedly.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger phrases are generic and one is truncated, which reinforces ambiguous invocation patterns instead of demonstrating precise, bounded usage. While less severe than the broad description and keyword list, unclear examples can train users or orchestrators to call the skill on incomplete or weak intent signals.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation, which allows the agent to trigger this capability without an explicit user request or tightly defined trigger conditions. Because the skill can influence responses in software/API documentation contexts, broad automatic activation increases the chance of unintended use, prompt-surface expansion, or invocation from ambiguous requests where the user did not clearly consent.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is so generic that it can activate on ordinary user phrasing rather than an explicit request to use this skill. That creates unnecessary skill invocation and context hijacking risk, where the agent may route unrelated requests into this workflow and produce unintended outputs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger descriptions do not define clear activation boundaries, so the skill may match ambiguous requests that only loosely relate to the requirement. In an agent environment, ambiguous routing increases the chance of incorrect tool selection, over-collection of context, and degraded safety because the skill can preempt more appropriate handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.