Back to skill

Security audit

OpenAPI Docs Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-assistance skill for OpenAPI/Swagger work, with no executable payload or persistence, though its routing text and demand evidence are low quality.

Before installing, treat the demand score and cited evidence as unreliable, and be aware that broad implicit triggers may make the skill appear for loosely related API or documentation requests. It is otherwise limited to producing local documentation guidance and artifacts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence is so broad and malformed that it could match ordinary user phrasing unrelated to this skill, causing accidental activation. In an agent environment, overbroad routing can send user data and tasks to an inapplicable skill, producing incorrect outputs and expanding the attack surface for prompt-routing abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are extremely generic and malformed, making it easier for the skill to activate outside its intended scope. Over-broad activation can cause the agent to route unrelated user requests into this skill, increasing the chance of inappropriate instruction application, context confusion, or prompt-surface abuse by attackers who intentionally use vague matching terms.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely broad and partly malformed, making activation likely on loosely related user requests rather than clear intent to use this specific skill. In an agent environment, overbroad routing can cause the wrong skill to take control, leading to misleading outputs, unintended data handling, or bypass of more appropriate safeguards tied to other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to capture many generic API, Swagger, or documentation requests, which can cause the agent to invoke this skill outside its intended boundaries. Over-broad routing increases the chance of misapplication, irrelevant actions, or prompt-surface expansion where the wrong skill handles sensitive or higher-risk requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are highly ambiguous terms like 'software-and-data', 'openapi', and 'rest api', which are common across many unrelated user requests. This can cause accidental invocation and skill overreach, reducing routing precision and potentially exposing users to unsuitable instructions or outputs from a mismatched skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description can activate on very broad topic labels like software-and-data, openapi, swagger, api documentation, and rest api without enough task-level constraints. Overbroad routing can cause the skill to be invoked for loosely related requests, leading to inappropriate guidance, context leakage across workflows, or bypass of more suitable specialized skills and guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger keywords are generic and unconstrained, which increases the chance of accidental or excessive activation on ordinary discussion of APIs or developer experience. In an agent setting, this can misroute requests, apply the wrong workflow, and expand the skill's effective authority beyond its intended documentation-assistance scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest enables implicit invocation while pairing it with a generic default prompt and broad usage scope, which can cause the skill to be selected in situations the user did not explicitly intend. That increases the risk of prompt-surface expansion, accidental data exposure to the skill, and execution of lower-trust instructions in unrelated API or software-documentation contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The evidence section claims strong validated demand for OpenAPI/Swagger documentation, but most cited links are unrelated topics such as Rust disk usage, C++ constants, and Windows Media Player. This creates a misleading provenance trail that can cause the agent selection system or reviewers to trust and activate the skill based on fabricated or irrelevant demand signals.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This trigger is ambiguous about when the skill should activate and does not clearly constrain scope to OpenAPI/Swagger work. Ambiguous routing conditions increase the chance of false activations, confusing users and enabling misuse of the skill-selection mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file lists separate English and Chinese instruction and guide files, but the README does not clarify how the user's preferred language is selected. This can imply a locale behavior without explicit user choice, which may conflict with language policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The file labels separate English and Simplified Chinese documentation variants, but this README itself is a zh-CN localized file and does not indicate any user choice or opt-in for language preference within the skill description. This may create a locale constraint concern if the skill defaults to a specific language without explicit user selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example triggers are malformed and truncated, so they do not provide reliable invocation guidance. Poor trigger examples can make routing behavior unpredictable and increase false activations or missed activations, especially when combined with already broad matching criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.