openapi-expert

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install well-known industry tools.
  • Fetches the @openapitools/openapi-generator-cli and @stoplight/spectral-cli packages via NPM for code generation and linting.
  • Pulls official Docker images swaggerapi/swagger-ui and redocly/redoc from public registries to serve API documentation.
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands intended for the agent to use or recommend.
  • Includes commands for generating client/server code using openapi-generator-cli.
  • Includes commands for linting specifications using spectral.
  • Includes docker run commands for local documentation hosting.
  • Note: The skill's YAML frontmatter restricts Bash tool usage to specific command patterns (openapi:*, swagger:*).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external OpenAPI specification files (YAML/JSON), which introduces a vulnerability surface if the ingested files contain malicious instructions.
  • Ingestion points: The skill reads OpenAPI specification files (e.g., openapi.yaml) to perform validation and code generation, as shown in SKILL.md.
  • Boundary markers: None identified. There are no explicit instructions to the agent to treat the content of API specifications as untrusted data.
  • Capability inventory: The skill has access to Read, Write, and Edit tools, as well as Bash execution (restricted by pattern), allowing it to modify the filesystem or execute tools based on the processed data.
  • Sanitization: None identified. The skill does not explicitly describe validation or sanitization of the input specification content beyond standard schema linting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:51 AM
Security Audit — agent-trust-hub — openapi-expert