openapi-expert
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install well-known industry tools.
- Fetches the
@openapitools/openapi-generator-cliand@stoplight/spectral-clipackages via NPM for code generation and linting. - Pulls official Docker images
swaggerapi/swagger-uiandredocly/redocfrom public registries to serve API documentation. - [COMMAND_EXECUTION]: The skill provides numerous shell commands intended for the agent to use or recommend.
- Includes commands for generating client/server code using
openapi-generator-cli. - Includes commands for linting specifications using
spectral. - Includes
docker runcommands for local documentation hosting. - Note: The skill's YAML frontmatter restricts Bash tool usage to specific command patterns (
openapi:*,swagger:*). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external OpenAPI specification files (YAML/JSON), which introduces a vulnerability surface if the ingested files contain malicious instructions.
- Ingestion points: The skill reads OpenAPI specification files (e.g.,
openapi.yaml) to perform validation and code generation, as shown inSKILL.md. - Boundary markers: None identified. There are no explicit instructions to the agent to treat the content of API specifications as untrusted data.
- Capability inventory: The skill has access to
Read,Write, andEdittools, as well asBashexecution (restricted by pattern), allowing it to modify the filesystem or execute tools based on the processed data. - Sanitization: None identified. The skill does not explicitly describe validation or sanitization of the input specification content beyond standard schema linting.
Audit Metadata