context7-auto-research

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install components from a third-party GitHub repository (BenedictKing/context7-auto-research) that is not affiliated with a known trusted vendor.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests library and framework documentation from the external Context7 API, creating a surface for indirect prompt injection where malicious documentation content could influence the agent's behavior.\n
  • Ingestion points: External documentation content fetched from the Context7 API and inserted into the agent's context.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified in the skill.\n
  • Capability inventory: The skill acts as a data provider that enriches the conversation context for React, Next.js, and Prisma related queries.\n
  • Sanitization: No sanitization, validation, or integrity checking of the external documentation data is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — context7-auto-research