Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk OpenAPI documentation helper, though its activation wording is broader than it needs to be.

Installers should treat this as a documentation-assistance skill for explicit OpenAPI or Swagger work. The publisher should narrow the activation phrases and implicit routing description so it is not selected for unrelated software or general REST API conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are so generic and template-like that they can cause the skill to activate outside its intended scope, increasing the chance of inappropriate routing or prompt-surface expansion. In an agent system, overly broad activation can expose users to incorrect tool use, unintended instructions, or confusion about what capability is being invoked.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and generic, causing the skill to activate on loosely related requests such as general software, API, or workflow questions. This can lead to unintended invocation, context hijacking, or the skill influencing conversations outside its intended scope, which is a security concern when skills may introduce hidden instructions or side effects.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description activates on very broad terms like 'software-and-data', 'openapi', 'swagger', and 'rest api' without enough narrowing conditions. This can cause the skill to trigger in unrelated conversations, leading to incorrect routing, prompt interference, or unreviewed instructions being injected into contexts where they do not belong.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The listed trigger keywords are overly generic and can match a wide range of harmless or unrelated developer queries. Over-broad triggers increase the chance of accidental activation, which can expose users to irrelevant instructions, create agent confusion, and amplify the effect of any unsafe behavior present in the skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger scope in the skill metadata is broad and mixes specific terms with generic categories like software-and-data and general needs for workflow, analysis, or implementation support. That can cause the skill to be invoked for loosely related requests, increasing the chance of unintended routing and irrelevant or overly authoritative responses in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are natural-language requests that are overly generic and repetitive, without strong constraints tying invocation to a well-scoped OpenAPI documentation task. This makes accidental activation more likely when users describe broad backend or platform needs, which can lead to misrouting and unsafe overreach of the skill's intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation while using a very broad and underspecified description, which can cause the agent to trigger this skill in contexts only loosely related to the user's request. That increases the chance of unintended data exposure, misleading assistance, or unsafe workflow execution because the skill may be selected without clear user intent or narrow routing criteria.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence begins with a generic phrase ('Help me ...'), which is broad enough to match many unrelated requests and can cause the skill to activate outside its intended OpenAPI/Swagger scope. Over-broad activation increases the chance of misrouting user tasks, producing irrelevant outputs, or overshadowing a more appropriate skill in multi-skill selection systems.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence ('I need a practical workflow for ...') is ambiguous and does not clearly anchor the request to API documentation work, making accidental invocation more likely. In a routing or orchestration context, ambiguous triggers can be exploited to steer general software requests into this skill, reducing reliability and potentially bypassing more suitable specialized handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.