Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-help skill with overly broad auto-invocation wording but no hidden code, persistence, or sensitive access.

Installers should expect a benign OpenAPI documentation assistant, but should consider narrowing its trigger wording or disabling implicit invocation if they want to avoid accidental activation on general API, backend, or documentation conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic and mechanically templated, making accidental or overly broad invocation more likely. In an agent environment, ambiguous triggers can route unrelated user requests into this skill, causing inappropriate instructions or outputs to be applied outside the intended OpenAPI-documentation use case.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are very broad and can activate the skill for generic software or API-related requests without clear scoping or consent. In an agent system, over-broad activation increases the chance this skill is invoked in the wrong context, leading to irrelevant guidance, prompt interference, or accidental takeover from a more appropriate skill.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description casts a wide net across broad terms like 'software-and-data', 'openapi', 'swagger', and 'api documentation' without strong boundary conditions. In agent routing systems, this can cause the skill to activate for loosely related requests, increasing the chance of inappropriate guidance, context hijacking, or accidental override of a more suitable skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences use highly generic phrasing such as 'Help me' and 'I need a practical workflow' with only loosely appended domain text, which weakens scope control. This makes it easier for the orchestrator or user prompts to match the skill in situations where OpenAPI documentation is not actually the primary task, leading to misrouting and potentially unsafe or irrelevant actions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and activation scope are broad enough that ordinary requests about software, APIs, or documentation could trigger it even when the user did not intend to invoke this specific skill. Over-broad routing can cause the wrong skill to handle prompts, leading to irrelevant guidance, policy bypass through unexpected tool selection, or expanded exposure of downstream components to unneeded inputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include common, high-frequency terms like 'software-and-data', 'openapi', 'swagger', 'api documentation', and 'rest api' without contextual constraints or negative cases. This increases the likelihood of accidental activation in many normal engineering conversations, which can misroute tasks and broaden the attack surface for prompt or workflow confusion.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation, but the trigger description is broad and vague rather than narrowly scoped to specific user intents or conditions. This can cause the agent to auto-select the skill in unrelated contexts, increasing the chance of unintended prompt injection exposure, overreach, or unexpected behavior from a skill whose content should be treated as untrusted.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence on this line is so broad and malformed that it can match ordinary user phrasing rather than a clearly scoped request for this specific skill. That increases the chance of unintended activation, causing the agent to route unrelated prompts into this skill and potentially override more appropriate handling or expose internal workflow behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger section lacks clear boundaries, includes repetitive templated language, and does not define exclusions for nearby but different requests. In a skill-routing system, ambiguous scope can lead to false-positive invocation, which is dangerous because the assistant may apply the wrong instructions or assumptions to user requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.