{"data":{"skill":{"slug":"wshobson-openapi-spec-generation","name":"openapi-spec-generation","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/documentation-generation/skills/openapi-spec-generation","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"3e87ad6d-d1eb-4194-93a1-9a69553a9673","skill_id":"700a0fbd-7acd-412b-b35c-8d0b167e6404","version":5,"content_hash":"0c26954c3197ab2e88e262e9f1bbbc1c","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static analyzer found command, URL, weak-crypto, and reconnaissance patterns in SKILL.md. Review found no malicious intent or prompt injection, but the skill includes legitimate install and CLI command examples that may modify the developer environment.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":900,"line_start":897},{"file":"SKILL.md","line_end":941,"line_start":903},{"file":"SKILL.md","line_end":977,"line_start":943},{"file":"SKILL.md","line_end":1004,"line_start":982}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":533,"line_start":533},{"file":"SKILL.md","line_end":534,"line_start":534},{"file":"SKILL.md","line_end":1025,"line_start":1025},{"file":"SKILL.md","line_end":1026,"line_start":1026},{"file":"SKILL.md","line_end":1027,"line_start":1027},{"file":"SKILL.md","line_end":1028,"line_start":1028}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Legitimate External Tool Commands","locations":[{"file":"SKILL.md","line_end":900,"line_start":897},{"file":"SKILL.md","line_end":977,"line_start":943},{"file":"SKILL.md","line_end":1004,"line_start":982}],"confidence":0.86,"description":"The skill provides bash examples that install npm packages globally and run OpenAPI validation, bundling, preview, and SDK generation tools. These commands are relevant to the skill, but they can change the local environment or write generated files if executed.","confidence_reasoning":"The command examples are direct and executable, but they match the documented purpose of OpenAPI linting and SDK generation. I found no evidence that they exfiltrate data or run hidden payloads."}],"low_findings":[{"title":"Hardcoded Example and Documentation URLs","locations":[{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":77,"line_start":67},{"file":"SKILL.md","line_end":534,"line_start":533},{"file":"SKILL.md","line_end":1028,"line_start":1025}],"confidence":0.91,"description":"The URL alerts are examples, local development addresses, and links to public OpenAPI-related documentation. They do not send credentials or make network requests by themselves.","confidence_reasoning":"The URLs are visibly documentation links or placeholder API server values. No surrounding code performs outbound transmission."},{"title":"False Positive Weak Cryptography Alerts","locations":[{"file":"SKILL.md","line_end":507,"line_start":496},{"file":"SKILL.md","line_end":918,"line_start":917},{"file":"SKILL.md","line_end":1021,"line_start":1016}],"confidence":0.88,"description":"The weak-cryptography alerts match OpenAPI security terms such as bearer authentication, JWT format, API key schemas, and security sections. I found no cryptographic implementation or weak hash algorithm use.","confidence_reasoning":"Keyword review found security documentation, not crypto code. The file contains no evidence of MD5, SHA-1, custom encryption, or password handling logic."},{"title":"False Positive Reconnaissance Alerts","locations":[{"file":"SKILL.md","line_end":253,"line_start":245},{"file":"SKILL.md","line_end":426,"line_start":395},{"file":"SKILL.md","line_end":804,"line_start":801}],"confidence":0.84,"description":"The reconnaissance alerts are caused by ordinary API schema identifiers, UUID formats, and response examples. These lines document API shapes and do not inspect the host system.","confidence_reasoning":"The cited content is OpenAPI and tsoa documentation syntax. I found no commands that enumerate files, users, networks, processes, or environment details."}],"dangerous_patterns":[{"title":"Environment-Modifying CLI Examples","locations":[{"file":"SKILL.md","line_end":900,"line_start":897},{"file":"SKILL.md","line_end":1004,"line_start":982}],"confidence":0.82,"description":"The skill shows global npm installation and generator commands. Users should review package sources and output paths before allowing an agent to run them.","confidence_reasoning":"The pattern is clearly present and can affect a local machine. It is still normal for this type of API tooling skill."}],"files_scanned":1,"total_lines":1029,"audit_model":"codex","audited_at":"2026-07-01T01:13:04.546+00:00","created_at":"2026-07-01T02:22:08.686477+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}