Back to skill

Security audit

Api Doc Writer Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly an API documentation helper, but it requests broad development activation plus command, file, API, and credential-related authority beyond its clearly defined documentation role.

Install only if you are comfortable with the agent using this skill during broad development work and potentially reading/writing files or running commands. Prefer using it only in a sandboxed project and avoid providing real API keys or callback URLs unless the provider and data flow are clear.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

High
Confidence
89% confidence
Finding
The skill advertises command execution, file handling, and API integration despite being presented as an API documentation writer. This capability expansion is dangerous because an over-permissioned skill can be induced to run shell commands or manipulate files unrelated to its stated purpose, increasing the risk of prompt-driven misuse or lateral impact on the host environment.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger condition is so broad that the skill may auto-activate for nearly any development-related task, including ones outside API documentation. In the context of a skill that also lists `exec`, `write`, and API-related behavior, overbroad activation increases the chance of unintended tool use, unsafe delegation, or user confusion about what actions the agent may take.

Static analysis

No suspicious patterns detected.