Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-help skill for OpenAPI and Swagger work, with no executable code, persistence, credential access, or hidden data movement found.

Installers should be aware that the skill may be invoked for somewhat broad API or developer-experience wording. It is best used when the request clearly concerns OpenAPI, Swagger, REST API documentation, schema generation, or validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples use very generic natural-language phrasing such as 'Help me' and 'I need a practical workflow,' which can match ordinary user requests and cause the skill to activate unintentionally. In an agent system, over-broad invocation increases the chance that this skill runs in the wrong context, leading to prompt hijacking of routing behavior, user confusion, or unexpected processing of unrelated inputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, templated, and likely to match ordinary user requests about OpenAPI or REST API documentation, which increases the chance of unintended skill activation. In an agentic environment, overbroad invocation can route user data and task execution through the wrong skill, causing confusion, unexpected actions, or expansion of the skill's operational scope beyond what the user explicitly intended.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and activation guidance are broad enough that ordinary requests about software, APIs, or documentation could unintentionally invoke this skill. Over-broad invocation increases the chance of context hijacking, incorrect tool selection, or unintended processing of user inputs under this skill's workflow.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include very general terms like 'software-and-data' and 'developer experience' alongside more specific API-doc terms. Such generic keywords can match many unrelated conversations, causing accidental activation and increasing the attack surface for prompt-routing mistakes or unintended behavior.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger phrases begin with highly common language such as 'Help me' and 'I need a practical workflow', which overlaps with normal user conversation patterns. While the examples alone do not execute code, they can encourage implementations or routers to over-match broad phrasing and invoke the skill inappropriately.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation, but the trigger description is broad and non-specific, making it easier for the agent to activate this skill in situations where the user did not clearly request it. This can cause unintended routing, unexpected disclosure of context to the skill, or unsafe overreach into tasks adjacent to API/documentation work.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing and activate the skill outside its intended scope. Over-broad activation can route unrelated prompts into this skill, causing inappropriate handling, reduced safety review fidelity, or context hijacking when another skill should have been selected.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage signals and trigger descriptions do not define clear boundaries for when the skill should or should not activate. Ambiguous activation criteria increase the chance of accidental invocation, misrouting, and over-collection of unrelated user context under a documentation-focused skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.