Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a simple OpenAPI documentation helper with broad routing text, but no hidden execution, data access, persistence, or destructive behavior.

Before installing, understand that this skill may activate on some broad API or documentation prompts because implicit invocation is enabled and the trigger examples are loose. It is otherwise a documentation-only helper, so the main practical risk is irrelevant or unintended assistance rather than unsafe system access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger sentences are generic and match broad phrases like 'help me' or 'I need a practical workflow' combined with a long requirement description, which can cause unintended invocation of this skill in contexts where the user did not explicitly request it. In an agent ecosystem, overbroad routing increases the chance of misfires, incorrect tool selection, and accidental exposure of internal instructions or irrelevant automated behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad, templated, and partially malformed, which increases the chance the skill is invoked unintentionally for loosely related requests. In an agent environment, overbroad activation can route user input into the wrong workflow, causing inappropriate data handling, confusing outputs, or bypass of more suitable skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough that it could activate for generic API, software, or documentation requests without clear boundaries. Over-broad activation can cause inappropriate tool routing, leading the agent to apply this skill in contexts it was not designed for and potentially produce irrelevant or unsafe guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include very general terms like 'openapi', 'swagger', and 'rest api' without requiring a documentation-specific intent. This increases the chance of accidental invocation on unrelated requests, which can misroute user tasks and amplify incorrect or incomplete assistance.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger sentences are malformed and do not clearly represent realistic user intents, reducing their value as safe routing guidance. Poor examples can cause ambiguous matching behavior and make the skill easier to invoke incorrectly, though the direct security impact is limited.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad and lack clear boundaries, especially terms like "software-and-data", "openapi", and "rest api" that can appear in many unrelated requests. This can cause the skill to activate in contexts where the user did not ask for OpenAPI documentation help, increasing the chance of irrelevant behavior, prompt hijacking surface, or unintended routing.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description defines invocation conditions too broadly by combining multiple generic domains and artifact types without clear exclusions. In an agent system, overbroad routing criteria can misclassify user intent and invoke this skill for tasks outside its safe operational scope, which weakens control over downstream behavior.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases are vague and do not show contrasting negative examples, so they fail to establish a reliable activation boundary. This makes it easier for ambiguous or loosely related user text to be interpreted as a match, causing accidental invocation and degraded routing precision.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt contains a very broad trigger phrase and generic wording that can cause the skill to be invoked in contexts beyond a user's clear intent. Because implicit invocation is also enabled, this increases the chance of accidental routing to this skill, which can expose users to unintended prompt injection surface, incorrect tool selection, or processing of sensitive API materials without an explicit request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence begins with a generic everyday phrase ('Help me ...'), which can cause the skill to activate for broad user requests that only loosely relate to OpenAPI documentation. Over-broad activation increases the chance of unintended routing, where the agent applies this skill in contexts it was not designed for and may produce irrelevant or misleading implementation guidance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger scope is ambiguous because the listed trigger sentences and keywords do not define strong activation boundaries, making it unclear when the skill should or should not run. In an agent environment, this can lead to mis-triggering on partially related software requests, causing inappropriate skill selection and reducing trust in the system's routing behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.