Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-helper skill with overly broad activation wording, but it does not contain code, hidden actions, credential handling, or persistence.

This skill is reasonable to install for OpenAPI or Swagger documentation help. Consider tightening its trigger phrases or disabling implicit invocation if you want to avoid accidental activation during general backend or API discussions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are so generic that the skill may activate for loosely related requests about APIs, documentation, or workflows without clear user intent. In an agent environment, over-broad activation can cause the wrong skill to take control, produce irrelevant artifacts, or influence task routing in ways the user did not request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and include generic requests like 'help me' and 'I need a practical workflow' tied to a long demand statement, which can cause the skill to activate outside a clearly scoped OpenAPI-documentation context. Over-broad activation increases the chance of prompt hijacking, unintended invocation, or incorrect routing of unrelated user requests into this skill, which can degrade security controls and produce unsafe or misleading outputs.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to match a wide range of software and API-related requests, which can cause unintended activation outside the narrow OpenAPI documentation use case. Over-broad triggering can route users into the wrong skill, producing irrelevant guidance and increasing the chance that downstream instructions are applied in inappropriate contexts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrases are malformed, truncated, and too vague to clearly delimit when the skill should activate. Poorly specified triggers increase accidental invocation and make it easier for unrelated prompts to satisfy activation heuristics, reducing reliability and potentially bypassing intended skill boundaries.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is extremely broad and includes generic problem framing around OpenAPI/Swagger help without strong gating conditions. This can cause the skill to activate in loosely related conversations, increasing the chance of prompt collision, unintended tool routing, or irrelevant instructions being injected into unrelated tasks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list contains broad, high-frequency terms such as 'software-and-data', 'openapi', and 'rest api' without requiring task-specific context. In a multi-skill system, these generic keywords can spuriously match common developer requests, causing accidental invocation and expanding the attack surface for misrouting or instruction interference.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger phrases are written as generic help requests and closely resemble ordinary user utterances. This increases the probability that unrelated conversational input will match the trigger pattern, leading to unnecessary or incorrect skill activation, though the downstream impact is limited by the non-privileged nature of the skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while providing only broad, generic activation language in its metadata. This can cause the agent to auto-select the skill for loosely related requests, increasing the chance that untrusted skill instructions influence behavior without an explicit user request or clear scoping.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is so broad and unnatural that it can match loosely related user requests and cause the skill to activate outside its intended scope. In an agent system, overbroad activation can route ordinary API or backend conversations into this skill unexpectedly, creating prompt-scope confusion and increasing the chance of irrelevant or policy-bypassing behavior through unintended tool selection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger is ambiguous because it describes a broad 'practical workflow' need without clearly limiting activation to OpenAPI/Swagger documentation tasks. Such ambiguity can cause accidental invocation for general backend workflow questions, making agent behavior less predictable and potentially exposing users to incorrect routing or unintended instruction context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.