Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill provides OpenAPI documentation guidance and has overly broad activation wording, but it contains no executable code, credential handling, persistence, or hidden high-impact behavior.

Installers should know this skill may be invoked for general API or developer-experience wording, not only explicit OpenAPI or Swagger tasks. Consider tightening triggers if precise routing matters, but the inspected package itself is a documentation workflow and does not appear to perform unsafe actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and partly malformed, so the skill could be invoked by loosely related requests rather than explicit user intent. In an agent environment, unintended invocation can cause the model to apply specialized instructions or workflows when the user did not ask for them, increasing the chance of context confusion, incorrect actions, or policy bypass through overmatching.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are so broad and template-like that they can match ordinary user requests about APIs and documentation, causing this skill to activate outside narrowly intended contexts. Over-broad activation increases the chance of prompt-routing mistakes, unnecessary context injection, and misuse of the skill in situations where more specific handling or least-privilege behavior would be safer.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description and activation guidance are broad enough that the skill may trigger during ordinary conversations about APIs, documentation, or developer experience rather than only when the user explicitly wants OpenAPI-documentation help. Over-broad activation can cause inappropriate routing, unnecessary context injection, or execution of the wrong workflow, which is a security-relevant quality issue when skills are treated as trusted automation components.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list contains generic phrases such as 'software-and-data', 'api documentation', and 'developer experience', which are likely to appear in many unrelated technical requests. This increases the chance of accidental invocation or prompt-surface expansion, making the system easier to steer into using this skill when it is not appropriate.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description and frontmatter scope are broad enough to overlap with common software engineering conversations, which can cause the skill to activate outside its intended context. Over-triggering is dangerous because it may inject irrelevant workflow constraints or documentation-generation behavior into unrelated tasks, reducing reliability and potentially steering users away from safer or more appropriate handling.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section lists broad keywords and permissive example phrases without clear gating conditions, making accidental activation likely in ordinary technical discussions about APIs or developer experience. In an agent system, ambiguous triggers can cause incorrect skill selection, leading to context pollution, wasted actions, or application of unsuitable guidance to user requests.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The default prompt uses a very broad natural-language trigger phrase tied to common software topics, which can cause the skill to be invoked in situations beyond the user's clear intent. Because implicit invocation is enabled, this increases the chance of unwanted routing, prompt-scope confusion, or accidental exposure of the skill's instructions during unrelated conversations about APIs or documentation.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence begins with a highly generic phrase ('Help me'), which can cause the skill to activate for ordinary requests that are not specifically about OpenAPI or Swagger documentation. Overbroad activation increases the chance of unintended routing, context confusion, and inappropriate use of the skill in unrelated conversations, which can degrade safety and reliability of agent behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.