documentation-lookup
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because it fetches documentation and code snippets from the external Context7 MCP service. If the documentation source contains adversarial instructions, it could influence the agent's behavior.
- Ingestion points: Content is ingested through the
query-docstool output as defined inSKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the fetched data.
- Capability inventory: The skill is intended for high-privilege environments like Claude Code or Cursor, which possess shell execution and file system access.
- Sanitization: The instructions do not define a process for sanitizing or validating the documentation content before it is processed.
- [DATA_EXFILTRATION]: The skill transmits user queries to an external service to resolve library IDs and retrieve documentation. While the instructions include a mandatory safety step to redact secrets (API keys, tokens) from queries before transmission, the user's search context and intent are still shared with the external service provider.
Audit Metadata