Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work, with some overly broad trigger wording but no unsafe access, persistence, or hidden execution behavior.

Before installing, be aware that this skill may activate for general API or developer-experience wording, not only explicit OpenAPI spec tasks. It appears safe for documentation assistance, but users who want precise routing may prefer narrower trigger wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are generic and broad enough to match ordinary user requests about OpenAPI, Swagger, workflows, or API documentation, which increases the chance the skill is invoked when the user did not explicitly intend it. Unintended invocation can cause prompt/context injection into unrelated tasks, surprising behavior, and over-application of the skill’s instructions across normal software questions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is scoped very broadly to common API and documentation terms, which can cause the agent to invoke this skill for many ordinary software requests that are only loosely related to OpenAPI generation. Over-broad activation increases the chance of inappropriate tool or workflow selection, producing irrelevant guidance, overshadowing more suitable skills, and expanding the attack surface for prompt-routing abuse.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases use generic wording like 'Help me' and 'I need a practical workflow' combined with truncated requirement text, which does not provide strong domain boundaries for reliable routing. If trigger examples are too vague, the skill may activate on ambiguous user requests, leading to misclassification and unintended execution paths in multi-skill environments.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill’s trigger conditions are broad and loosely bounded, combining generic terms like 'software-and-data', 'openapi', 'swagger', 'api documentation', and 'rest api' with expansive descriptive language. This can cause the skill to activate for unrelated or only partially related requests, leading to inappropriate routing, user confusion, or accidental exposure of capability-specific instructions in contexts where they are not needed.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is written as a broad natural-language request that could match many ordinary user queries beyond explicit OpenAPI documentation tasks. Combined with implicit invocation, this increases the chance the skill is auto-selected in contexts the user did not clearly intend, which can cause prompt-scope overreach or unintended handling of requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is overly broad and malformed, making it likely to activate on vague everyday phrasing rather than a clearly scoped OpenAPI-documentation request. In an agent routing context, this can cause mis-selection of the skill, leading the system to inject irrelevant instructions or artifacts into unrelated conversations and reducing trust in downstream outputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list lacks clear scope boundaries and includes ambiguous, truncated examples that do not reliably distinguish this skill from general software-help requests. Such ambiguity increases accidental invocation risk, which can be exploited indirectly by prompting with generic phrasing to force the wrong skill path and pollute task handling or context selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.