oas-api-spec-generator

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is centrally coherent: it aims to produce OpenAPI 3.2.0 specifications for third-party APIs by leveraging official specs when available and otherwise compiling from provider documentation. The data flows are read-only with respect to credentials, and the only write-out is the generated YAML specification. The risk footprint is low to moderate and appears proportional to its purpose (documentation tooling). Ensure proper validation of generated specs and confirm source URLs to prevent unintentionally propagating outdated or incorrect API details. Overall, the tool remains benign with respect to the stated purpose, with a modest security risk arising from external content fetches if upstream sources are compromised; this remains a standard risk for any docs-generation workflow.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/deepparser%2Fskills%2Foas-api-spec-generator%2F@c88f51817741cf11f52de98705ccd9e49b3adbed