Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation workflow helper for OpenAPI and Swagger tasks, with no code execution, credential access, persistence, or hidden data handling.

Install this if you want help producing or reviewing OpenAPI/Swagger documentation. Be aware it may be invoked for broad API-documentation-related prompts because implicit invocation is enabled and the trigger terms are general; use explicit skill invocation when you want predictable routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are generic and include broad natural-language patterns like 'Help me' and 'I need a practical workflow', which can cause the skill to activate in contexts beyond explicit user intent. In an agent system, unintended invocation can route unrelated prompts into this skill, leading to incorrect handling, prompt hijacking opportunities, or leakage of context into the wrong workflow.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and include generic terms like software-and-data, openapi, swagger, api documentation, and rest api without meaningful scope limits. This can cause the skill to activate in situations where it was not intended, increasing the chance of prompt hijacking, irrelevant invocation, or accidental override of a more appropriate skill during user requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad, generic API terms such as 'openapi', 'swagger', 'api documentation', and 'rest api', which are common in many unrelated conversations. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, prompt contamination of unrelated tasks, or over-application of the skill's workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are vague and largely restate the requirement rather than showing precise, bounded activation criteria. Ambiguous examples increase the chance that orchestration or downstream agents invoke the skill for loosely related requests, which can degrade response quality and create prompt-selection confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and activation criteria are broad enough to match many generic API, Swagger, or REST-related requests, which can cause the skill to be invoked outside its intended validated-demand use case. Over-broad routing increases the chance of inappropriate context injection, incorrect automation, or interference with more specialized skills handling API design, security, or implementation tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The listed trigger keywords are very generic terms such as 'openapi', 'swagger', 'api documentation', and 'rest api', which are likely to match routine technical conversations that do not actually require this skill. This can lead to unintended invocation, poor task routing, and accidental application of this workflow in contexts where more precise or safer handling is needed.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation while using a very broad description/default prompt that can match common user requests about APIs, Swagger, or documentation. This increases the chance the agent invokes the skill unexpectedly, which can cause prompt-scope expansion, unintended data exposure to the skill context, or unreviewed downstream actions without clear user intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing such as asking for help with backend or platform work, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that the agent applies the wrong workflow, injects irrelevant instructions into unrelated conversations, or can be intentionally invoked by a prompt crafted to hijack routing.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation wording 'I need a practical workflow for...' is too generic and does not sufficiently constrain the subject matter, making accidental or adversarial activation more likely. In a routing system, vague triggers can let users steer the agent into this skill from loosely related requests, reducing trust boundaries between specialized skills and increasing prompt-surface exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.