Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-helper skill for OpenAPI/Swagger work; its activation rules are broader than ideal, but the artifacts do not request dangerous access or perform hidden actions.

Before installing, be aware that this skill may be selected for some broad API, documentation, or developer-experience requests. Use explicit OpenAPI or Swagger wording when you want it, and disable implicit invocation if you need tighter routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences include generic phrases like 'Help me' and 'I need a practical workflow' wrapped around broad requirement text, which can cause the skill to activate in situations not clearly requesting this specific capability. In agent systems, overbroad activation increases the chance of unintended routing, context leakage into the wrong skill, or execution of an irrelevant workflow on user input that only partially matches.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, repetitive, and loosely scoped, which can cause the skill to be invoked in contexts where the user did not clearly request OpenAPI documentation help. In an agent environment, ambiguous invocation boundaries can lead to unintended activation, context hijacking, or the wrong skill handling user input, increasing the chance of unsafe or incorrect downstream actions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad and loosely bounded, especially terms like "openapi", "swagger", "rest api", and "developer experience", which can appear in many ordinary requests. This can cause the skill to activate outside its intended scope, leading to irrelevant guidance, reduced routing precision, or accidental interception of unrelated user tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are highly generic (e.g. "Help me" / "I need a practical workflow") and closely resemble normal user requests, while embedding the skill's broad demand statement rather than concrete routing boundaries. This increases the chance of over-triggering the skill on common support queries that only partially relate to OpenAPI documentation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation, but the manifest does not define clear trigger constraints or scope boundaries for when it should auto-activate. That can cause the agent to invoke this skill on loosely related user requests, exposing users to unintended prompt influence, incorrect tool routing, or over-broad processing without explicit consent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence "Help me ..." is overly broad and closely matches normal conversational language, which can cause the skill to activate in situations far beyond OpenAPI documentation help. Overbroad activation increases the risk of incorrect routing, prompt hijacking of unrelated tasks, and unintentional disclosure or processing of irrelevant user/project context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description and example sentences do not define clear boundaries for when the skill should or should not activate, making invocation ambiguous. This ambiguity can cause accidental activation on unrelated backend or documentation requests, reducing reliability and potentially exposing the skill to adversarial phrasing designed to force misrouting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.