Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk documentation workflow skill for OpenAPI/Swagger work, with broad activation wording but no executable payload, persistence, credential handling, or hidden data flow.

Safe to install for OpenAPI/Swagger documentation help, but expect occasional over-activation on general REST API or documentation prompts because the trigger wording is broad. Users who want tighter routing should invoke it explicitly by name or narrow the trigger phrases before publishing broadly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger sentences are broad, repetitive, and loosely scoped, which can cause the skill to activate for vague references to OpenAPI, Swagger, or general workflow help rather than a clearly intended request. In an agent environment, overbroad activation can route unrelated user prompts into this skill, increasing the chance of misapplication, prompt confusion, or unintended handling of user data and instructions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad, generic, and partially templated, which increases the chance the skill is invoked unintentionally when a user mentions common OpenAPI or workflow-related requests. In an agent ecosystem, ambiguous invocation can route user input into the wrong skill, causing confusion, over-collection of context, or unexpected actions even if the skill itself is not overtly harmful.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough that it could match generic software or API-related requests outside the intended OpenAPI documentation scope. Overbroad routing can cause unintended invocation, leading the agent to apply this skill in inappropriate contexts and potentially produce misleading or unsafe guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains broad technical terms such as 'software-and-data' and 'rest api' that may appear in many unrelated requests. This increases the chance of accidental skill activation, which can interfere with correct tool or skill selection and reduce trust in the system's routing behavior.

Vague Triggers

Low
Confidence
87% confidence
Finding
The example trigger sentences are truncated and malformed, so they do not reliably communicate when the skill should be invoked. Poor invocation examples can amplify misrouting by training users or downstream systems on ambiguous or broken activation patterns.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and trigger criteria are broad enough that the skill may activate for loosely related requests, increasing the chance of unintended routing. In a documentation-generation skill, this can cause irrelevant or overconfident guidance to be applied where a more appropriate skill or general handling was needed, reducing reliability and potentially influencing technical changes without proper context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases use generic help-seeking language that is not sufficiently specific to OpenAPI documentation work. This makes accidental activation more likely, especially when users ask for general workflows or implementation help, which can misroute the interaction and degrade safety and task accuracy.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation, but the metadata shown does not provide a narrowly scoped activation boundary. That makes it easier for ordinary user requests about APIs, Swagger, or documentation to trigger the skill unexpectedly, increasing the chance of overbroad tool use or prompt-routing abuse. In this context, the skill is broadly framed around common backend and API tasks, which makes accidental or adversarial invocation more likely rather than less.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses broad natural-language wording covering software-and-data, OpenAPI, Swagger, API documentation, REST APIs, workflows, artifacts, checklists, analysis, and implementation support. This overlaps heavily with ordinary engineering requests, so the skill may be invoked in situations the user did not specifically intend, creating routing ambiguity and increasing the attack surface for prompt injection or unintended capability exposure.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence begins with a broad conversational phrase ('Help me ...'), which can cause the skill to activate in contexts where a user is asking a general question rather than explicitly requesting this specific OpenAPI documentation workflow. Over-broad activation increases the chance of unintended routing, prompt hijacking through loosely related requests, or suppression of more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is ambiguous because it maps a vague request for a 'practical workflow' to a long requirement description rather than a clear, bounded user intent. This can cause accidental invocation for adjacent software tasks, expanding the skill's execution surface and making misrouting or prompt-context confusion more likely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.