context7-skills

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute ctx7 CLI commands for managing skill configurations and installations.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external repositories via the ctx7 skills install and ctx7 skills info commands as part of its core functionality.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of external 'skills' from remote repositories. Since these skills contain instructions and potential scripts for the agent, this process constitutes a form of remote code execution intended by the skill's design.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to the way it handles external data.
  • Ingestion points: Untrusted metadata (such as skill names and descriptions) is ingested from external repositories during search and info operations.
  • Boundary markers: There are no boundary markers or instructions to ignore embedded commands; the skill instructions specifically require preserving entry text 'as-is'.
  • Capability inventory: The skill environment includes Bash execution and WebFetch capabilities.
  • Sanitization: No sanitization or validation is applied to data retrieved from remote sources before it is displayed to the user or processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — context7-skills