Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple OpenAPI documentation helper with overly broad activation wording but no hidden code execution, credential access, persistence, or destructive behavior.

Installers should be aware that this skill may activate more often than intended for generic REST API or developer-experience questions. It is best used when the request explicitly involves OpenAPI, Swagger, API specs, or REST API documentation work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad, repetitive, and close to ordinary user phrasing, which increases the chance the skill is invoked when the user did not explicitly intend to use it. In an agent ecosystem, unintended invocation can cause the model to follow the wrong workflow, expose unrelated context to the skill, or override a more appropriate capability, creating a prompt-routing and least-surprise problem.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are extremely broad and include generic help-seeking language, which raises the chance that the skill is invoked in contexts the user did not specifically intend. In an agent ecosystem, over-broad activation can cause the wrong workflow to run, leading to confused delegation, disclosure of unnecessary context to the skill, or unsafe task execution assumptions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description and usage criteria are broad enough that the skill may activate for general software/API discussions rather than clear, intentional invocation. Over-broad routing can cause the agent to apply this skill in contexts it was not meant for, increasing the chance of irrelevant guidance, prompt-scope confusion, or unintended handling of sensitive technical content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list contains generic terms such as 'software-and-data', 'api documentation', 'rest api', and 'developer experience', which are common across many unrelated conversations. This creates trigger collisions where the skill may be selected unnecessarily, potentially overriding more appropriate skills or causing the agent to follow an ill-fitting workflow.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example triggers are malformed and truncated, so they do not establish clear or safe invocation boundaries for when the skill should run. Ambiguous examples can weaken routing quality and make accidental invocation more likely, though the impact is lower than explicit unsafe instructions or code execution behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
该技能的描述和适用范围包含较宽泛的技术主题词,如 software-and-data、openapi、swagger、api documentation、rest api,且缺少明确边界条件,容易在普通技术讨论中被误触发。误触发会让代理在不需要时切换到该技能流程,带来不相关建议、上下文偏移或错误执行路径,属于真实的技能路由/范围定义问题。

Vague Triggers

Medium
Confidence
95% confidence
Finding
关键词触发列表覆盖面过大,并且没有提供反例、优先级或歧义消解规则,因此与常见开发者对话高度重叠。由于该技能面向 API、文档、开发体验等常见话题,这种宽触发在实际代理系统中更容易造成频繁误选,从而干扰正确技能调用或导致输出偏题。

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation but does not define narrow trigger constraints or a specific activation scope. That means the agent may auto-select this skill for broad, loosely related requests, increasing the chance of unintended activation, prompt-surface expansion, and misuse in contexts the skill was not meant to handle.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so broad and malformed that it could cause accidental activation on ordinary user requests that merely contain common help-seeking language. In a routing or skill-selection system, this can hijack intent resolution, causing the agent to invoke this skill when the user did not explicitly ask for OpenAPI documentation support.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger is ambiguous because it describes a vague need for a 'practical workflow' without clearly constraining when the skill should activate. Such ambiguity increases the chance of misrouting unrelated backend, platform, or workflow questions into this skill, reducing reliability and potentially exposing users to irrelevant or incorrect automated assistance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.