documentation-lookup

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because it fetches documentation and code snippets from the external Context7 MCP service. If the documentation source contains adversarial instructions, it could influence the agent's behavior.
  • Ingestion points: Content is ingested through the query-docs tool output as defined in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the fetched data.
  • Capability inventory: The skill is intended for high-privilege environments like Claude Code or Cursor, which possess shell execution and file system access.
  • Sanitization: The instructions do not define a process for sanitizing or validating the documentation content before it is processed.
  • [DATA_EXFILTRATION]: The skill transmits user queries to an external service to resolve library IDs and retrieve documentation. While the instructions include a mandatory safety step to redact secrets (API keys, tokens) from queries before transmission, the user's search context and intent are still shared with the external service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — documentation-lookup