openapi-spec-builder

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill is conceptually aligned with its purpose of generating OpenAPI specifications and operates within a reasonable, self-contained scope. The primary security concern is inadvertent embedding of user-supplied secrets (e.g., passwords or API keys) into the generated specification if the prompts contain them. No evident download/execution, credential forwarding to third-party tooling, or exfiltration mechanisms are described. To improve safety, enforce redaction/sanitization of secrets, add an explicit user confirmation step before exporting production-ready specs, and validate that all $ref references resolve within the generated document.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:30 AM
Package URL
pkg:socket/skills-sh/ehtbanton%2Fclaudeskillsrepo%2Fopenapi-spec-builder%2F@510ada84a181f365ed57fdcdf4977a7a24d9acc8