Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk OpenAPI documentation helper, though its activation wording is broad and should be tightened.

Installers should understand that this skill may activate too broadly around generic API or developer-experience requests; it is otherwise a documentation workflow helper with no observed credential, persistence, or execution behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The cited evidence largely does not substantiate the stated requirement for OpenAPI/Swagger documentation help; several links appear unrelated to API documentation. In a skill-selection pipeline, mismatched evidence can cause the agent to activate or prioritize this skill under false pretenses, degrading trust and potentially steering users into irrelevant or incorrect workflows.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger sentences are broad, repetitive, and not clearly bounded by specific user intent or exclusion criteria. This can cause the skill to activate in contexts where a user merely mentions related terms, leading to inappropriate routing, unintended prompt injection surface expansion, or disclosure of irrelevant generated guidance.

Vague Triggers

Low
Confidence
74% confidence
Finding
The activation description lists keywords and trigger sentences but does not define when the skill should not be used. This ambiguity increases the chance of accidental invocation and workflow confusion, though the file itself does not contain direct code execution or exfiltration behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad, repetitive, and partially malformed, which can cause the skill to activate in contexts that only loosely mention OpenAPI or documentation work. In an agent environment, overbroad activation increases the chance of unintended invocation, context capture, or the model applying this workflow when a more appropriate or safer skill should handle the request.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to match generic software, API, and documentation requests, which can cause unintended activation outside its narrow purpose. Over-broad routing is dangerous because it may steer unrelated user requests into this skill, producing irrelevant guidance, masking better-suited skills, or expanding the influence of any unsafe downstream instructions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers are malformed and overly general, making activation ambiguous and increasing the chance the skill is invoked for partial phrase matches or unrelated prompts. In a routing system, unclear triggers can degrade tool selection reliability and broaden the operational surface of the skill beyond its intended documentation-focused scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
该技能的描述与适用范围使用了较宽泛的技术术语和需求表述,缺少明确排除条件,容易在仅泛泛提到 API、Swagger 或软件数据相关话题时被误触发。误触发会让代理进入与用户真实意图不匹配的工作流,导致不必要的操作、错误建议或上下文偏移。

Vague Triggers

Medium
Confidence
95% confidence
Finding
关键词列表包含 software-and-data、openapi、swagger、api documentation、rest api、developer experience 等常见词汇,但未增加上下文约束,特异性不足。攻击者或普通用户只需在无关请求中嵌入这些词,就可能诱导系统调用该技能,造成提示劫持式的路由偏差或扩大技能暴露面。

Vague Triggers

Low
Confidence
87% confidence
Finding
示例触发句采用通用求助表达,如“Help me”或“I need a practical workflow”,没有展示什么情况下不应触发该技能。这会弱化路由边界,使系统更容易把普通帮助请求错误归类到 OpenAPI 文档生成场景,影响响应准确性。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation, but the trigger description is broad and underspecified, covering general topics like software, OpenAPI, Swagger, API documentation, and implementation support. This can cause the agent to invoke the skill in situations the user did not clearly intend, expanding the skill’s authority and increasing the chance of prompt-scope confusion, unintended data exposure to the skill, or abuse through loosely related prompts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence begins with an overly broad everyday phrase ('Help me ...'), which creates weak activation boundaries. Broad triggers can cause accidental invocation in unrelated conversations, leading the agent to apply this skill when the user did not intend it and increasing the chance of misrouting or prompt-surface abuse.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger uses ambiguous broad phrasing ('I need a practical workflow for ...') without clear boundaries tied to OpenAPI/Swagger tasks. Ambiguous triggers raise the likelihood of unintended activation and can crowd out more appropriate skills, especially in systems that match on approximate language.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.