oas-api-spec-generator
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill is centrally coherent: it aims to produce OpenAPI 3.2.0 specifications for third-party APIs by leveraging official specs when available and otherwise compiling from provider documentation. The data flows are read-only with respect to credentials, and the only write-out is the generated YAML specification. The risk footprint is low to moderate and appears proportional to its purpose (documentation tooling). Ensure proper validation of generated specs and confirm source URLs to prevent unintentionally propagating outdated or incorrect API details. Overall, the tool remains benign with respect to the stated purpose, with a modest security risk arising from external content fetches if upstream sources are compromised; this remains a standard risk for any docs-generation workflow.