Back to skill

Security audit

Openapi Docs Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation helper for OpenAPI/Swagger work and does not contain code, persistence, credential handling, or hidden actions.

Safe to install for OpenAPI/Swagger documentation help. Be aware that it may be invoked on broader API-related prompts because implicit invocation is enabled and the trigger language is loose; users who want tighter behavior should narrow the activation terms or invoke it explicitly only for OpenAPI/Swagger documentation tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is so generic that it can activate on ordinary user language rather than a clear, deliberate request for this specific skill. That creates unintended skill invocation and prompt-routing risk, where unrelated conversations may be steered into this skill and its instructions or assumptions may influence outputs outside the intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match ordinary requests about APIs, documentation, or workflows, which can cause the skill to activate outside the author's intended scope. Over-broad activation increases the chance of prompt hijacking at the routing layer, unintended tool or skill selection, and user confusion when a more appropriate skill should have handled the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are generic and broad enough to match ordinary conversation about OpenAPI, Swagger, or REST APIs, which increases the chance of unintended skill activation. In an agent environment, accidental invocation can route user requests into an unexpected workflow, causing confusing behavior, context leakage into the skill, or incorrect automation on unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and use conditions are broad enough to activate on many generic software or API-related requests, which can cause the agent to invoke this skill outside its intended scope. Over-broad routing is dangerous because it can override a more appropriate skill or cause untrusted instructions in this skill to shape responses in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Keywords like 'software-and-data', 'openapi', 'swagger', and especially 'developer experience' are ambiguous and can match many unrelated prompts. This increases the chance of accidental invocation, expanding the skill's influence beyond API documentation and creating prompt-routing risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

技能描述中的适用范围较宽,覆盖多个常见技术主题,并以“当用户提出…时使用”作为触发条件,但缺少明确的排除条件和优先级边界。这会导致路由器在一般性 API、软件或文档请求中误触发该技能,造成上下文偏移、错误建议或不必要暴露技能能力。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

触发关键词包含较通用术语,如“software-and-data”“rest api”“developer experience”,这些词在大量无关请求中也会出现,且没有配套否定条件。这会扩大技能匹配面,增加误调用概率,并可能干扰更适合的技能或基础助手行为。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill enables implicit invocation while advertising a very broad default prompt covering common OpenAPI, Swagger, API documentation, and implementation-help requests. That increases the chance the agent will auto-select this skill in situations the user did not explicitly intend, causing unreviewed prompt/context transfer into the skill and potentially expanding the skill’s authority or exposure surface.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description and examples do not define strong boundaries for when the skill should or should not activate, making routing ambiguous. In systems that auto-select skills from natural language, this ambiguity can cause over-selection, misrouting, and unintended exposure of the skill's behavior in contexts where it is not relevant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file is named as a Chinese-language README, but key descriptive and trigger content is presented in English rather than offering a language choice or clearly documenting the locale behavior. For a locale-specific file, this may force English on users expecting Simplified Chinese content.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger sentences use generic phrasing like 'Help me' and 'I need a practical workflow' without clear boundaries, which can train or encourage loose activation behavior. While less severe than the metadata fields, such examples still make misrouting more likely by normalizing invocation from vague requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

示例触发句采用高度通用的措辞,如“Help me”或“I need a practical workflow”,并直接拼接需求描述,容易与普通求助表达重叠。示例会影响触发器或作者后续复制模式,从而进一步强化宽泛匹配,导致误选该技能。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.