Back to skill

Security audit

Openapi Docs Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation helper for OpenAPI/Swagger work, with some overly broad activation wording but no hidden execution, persistence, credential access, or destructive behavior.

Before installing, be aware that this skill may activate on broad API or developer-experience requests because implicit invocation is enabled and the trigger examples are imprecise. Use explicit OpenAPI/Swagger prompts when possible, and review generated documentation before applying it to a production service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentences are malformed and broad enough that an agent may activate this skill on ambiguous requests that only loosely match the intended OpenAPI/Swagger use case. Over-broad activation can cause unintended routing, prompt-context contamination, or the skill being invoked when a more appropriate or safer workflow should handle the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, templated, and partially generic, which increases the chance that ordinary user requests about APIs or documentation will invoke this skill unintentionally. Unintended invocation can route users into the wrong workflow, cause misleading outputs, or expose downstream systems to unnecessary processing when multiple skills compete for similar prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to match a wide range of normal developer requests involving APIs, documentation, or software-and-data topics, which can cause unintended activation. Over-broad routing increases the chance that this skill handles requests outside its intended scope, leading to irrelevant guidance, context leakage across skills, or reduced reliability of agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The listed trigger keywords include generic terms such as 'software-and-data' and 'developer experience' that commonly appear in unrelated technical conversations. In a skill-selection system, such ambiguous keywords can cause frequent false activations, making the agent apply this skill in contexts where it is not appropriate and potentially interfering with safer or more relevant workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and trigger conditions are broad enough that the agent may invoke this skill for loosely related requests, causing unintended routing. While this is not a code-execution issue, overbroad activation can expose users to irrelevant instructions, create confusion, or bypass more appropriate specialized skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example trigger phrases begin with generic conversational language like 'Help me' and 'I need', paired with vague content, which increases accidental matching during normal user interactions. In a skill-routing system, this can cause the skill to activate when the user did not intend to request OpenAPI documentation support.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation while using a very broad default prompt tied to common terms like OpenAPI, Swagger, API documentation, and practical workflow help. This can cause the agent to invoke the skill in situations the user did not explicitly request, creating prompt-routing risk, unexpected behavior, and possible overexposure of the skill’s instructions or generated actions in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger block is ambiguous and lacks clear scope boundaries, with templated phrases that are truncated and not specific enough to reliably distinguish this skill from adjacent documentation or software-help tasks. Ambiguous activation logic can be exploited indirectly through prompt phrasing collisions, causing the agent to select this skill in the wrong context and potentially suppress a more appropriate or safer skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence at line 80 is overly broad and overlaps with ordinary user phrasing, increasing the chance that the skill activates when a user did not explicitly intend to invoke it. This can cause misrouting of requests, inappropriate application of the skill's workflow, and reduced trust in the agent's behavior, especially in environments with many skills competing on natural-language triggers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The user-facing README includes multiple Chinese link titles alongside English content, but it does not explain whether language selection is intentional or user-driven. This can create an implicit locale inconsistency in a user-facing skill description without documenting a choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Although this is labeled as a Chinese README, key descriptive content about the skill's purpose and target users is presented in English. This can violate language/locale expectations because the file does not indicate that English output is optional or provide an explicit language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example trigger sentences are malformed and nonspecific, which weakens activation boundaries and makes it harder to understand the intended routing behavior. Poor trigger examples can propagate misconfiguration or training ambiguity, indirectly increasing the likelihood of accidental invocation of this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.