Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk OpenAPI documentation helper, but its activation wording is broader and messier than it should be.

Install this only if you want an automatically invokable helper for OpenAPI or Swagger documentation work. Be aware it may activate on some broader API or developer-experience requests, so review its output when the request is not clearly about API specs or documentation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are generic and can match common user requests about OpenAPI, Swagger, or API documentation without strong disambiguation. This increases the chance of unintended skill activation, causing the agent to apply this skill in contexts where the user did not explicitly request it, which can lead to incorrect actions, irrelevant outputs, or interference with safer or more appropriate skills.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are broad and include generic help-seeking language, which can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. In an agent setting, unintended invocation can route user requests into the wrong workflow, leading to incorrect actions, confusion, or overcollection of context, even though this file does not itself contain direct code execution or exfiltration behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description and invocation guidance are broad enough to match many ordinary software requests beyond narrowly scoped OpenAPI documentation tasks. Over-broad routing can cause the agent to invoke this skill in unintended contexts, increasing the chance of irrelevant advice, prompt-scope confusion, or accidental processing of inputs that should have been handled by a different, more constrained skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The keyword list includes generic phrases like 'software-and-data' and 'developer experience' that are far broader than the actual skill purpose. Such unspecific triggers can cause inappropriate auto-selection of the skill, which may misroute user requests and expand the skill's influence beyond its intended safety and competency boundaries.

Vague Triggers

Low
Confidence
77% confidence
Finding
The example trigger sentences are malformed and truncated, so they do not provide clear, bounded examples of when the skill should activate. Poorly formed trigger examples can weaken routing precision and make it harder to distinguish legitimate invocations from unrelated requests, though the security impact is lower than overly broad trigger definitions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad enough to overlap with ordinary technical conversations about APIs, Swagger, or developer experience, which can cause the skill to activate when the user did not actually request this specialized workflow. In an agent setting, overbroad activation can lead to context hijacking, irrelevant instruction injection, or unintended steering of the assistant's behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases use highly generic English wording that lacks clear scope boundaries, making it easier for unrelated requests to match. This increases the chance of accidental invocation and exposes the agent to unnecessary instruction precedence from the skill content in contexts where it is not appropriate.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while using a very broad default prompt tied to common topics like OpenAPI, Swagger, API documentation, and REST APIs. This can cause the agent to auto-select the skill in contexts the user did not explicitly intend, increasing the risk of prompt hijacking, unintended data exposure to the skill, or confusing execution paths when handling general software requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and malformed that it can match ordinary user phrasing and cause the skill to activate outside its intended scope. Overbroad activation is dangerous because it can unexpectedly steer conversations into this skill's workflow, override more appropriate tools, or let an attacker deliberately invoke the skill in unrelated contexts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger is ambiguous about when the skill should activate and does not clearly constrain scope to OpenAPI/Swagger documentation work. Ambiguous triggers increase the chance of accidental or adversarial invocation, which can misroute user requests and create unsafe or incorrect task handling in a multi-skill environment.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.