Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work, with no executable code or hidden access, though its activation wording is overly broad.

Before installing, be aware that this skill may trigger on broad API-related wording. It is best used when you explicitly want help generating, validating, reviewing, or improving OpenAPI/Swagger documentation for REST APIs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are generic and templated enough that the skill could activate in situations where the user did not clearly request this specific capability. Over-broad activation increases the chance of unintended skill selection, which can misroute user requests, expose irrelevant instructions, or interfere with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, templated, and partially malformed, which increases the chance that ordinary user requests about OpenAPI, Swagger, or API docs will invoke the skill unintentionally. In an agent environment, overbroad activation can route user input into the wrong workflow, causing unnecessary processing, context confusion, or execution of capabilities the user did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description includes very broad routing terms such as 'software-and-data', 'openapi', 'swagger', 'api documentation', and 'rest api', plus generic phrasing like 'needs a practical workflow, artifact, checklist, analysis, or implementation support'. This can cause the skill to activate for many unrelated engineering requests, increasing the chance of inappropriate tool selection, prompt hijacking of user intent, or unnecessary exposure of the skill's instructions in contexts where it was not intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include broad/common phrases like 'software-and-data', 'api documentation', and 'developer experience' that are not specific enough to this skill. Overbroad triggers can cause accidental invocation on unrelated prompts, which degrades routing integrity and may lead the system to apply this skill's instructions where they do not fit the user's request.

Vague Triggers

Low
Confidence
83% confidence
Finding
The example trigger sentences are malformed and do not establish a clear invocation boundary, making it harder for routing systems or users to understand when this skill should apply. Ambiguous examples increase misrouting risk and may broaden activation beyond the intended OpenAPI-documentation use case.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and activation guidance are broad enough that ordinary discussions about APIs, software/data, or developer experience could unintentionally trigger this skill. Overbroad routing can cause the agent to select an irrelevant skill, leading to confused execution paths, disclosure of unnecessary context to the skill, or reduced reliability in downstream tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes generic terms like 'software-and-data', 'rest api', and 'developer experience' without scope boundaries, making accidental invocation likely during unrelated technical conversations. In agent environments, ambiguous keyword activation increases misrouting risk and may cause inappropriate tool/skill use in contexts where the user did not request OpenAPI documentation help.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is broadly worded and can cause the skill to be invoked in situations that only loosely relate to OpenAPI or API documentation. With implicit invocation enabled, this increases the chance of over-triggering the skill, causing unintended context use, confused task routing, or inappropriate application of the skill to user requests outside its intended scope.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrase is broad enough to match common user language rather than a narrowly scoped invocation, which can cause the skill to activate in contexts where the user did not intend to use it. That increases the risk of inappropriate routing, prompt hijacking opportunity through unrelated conversations, and accidental disclosure or generation of artifacts outside the skill’s intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is ambiguous and does not clearly define when the skill should or should not run, creating overlap with many ordinary developer-assistance requests. In practice this can make the agent select the skill too often, leading to misrouting, reduced predictability, and greater exposure to adversarial prompt content embedded in loosely related requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.