documentation-lookup

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external documentation from a third-party source (Context7), which could contain adversarial instructions designed to influence the agent's behavior. While the skill instructs the agent to answer based on the documentation, it lacks explicit safety instructions or boundary markers to differentiate between informational data and executable instructions.
  • Ingestion points: Documentation content fetched from the query-docs tool output based on user-provided library names and queries.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to treat the documentation output as untrusted data.
  • Capability inventory: The skill utilizes MCP tools (resolve-library-id, query-docs) which involve network communication to retrieve external content.
  • Sanitization: The skill provides proactive instructions to redact sensitive user data (API keys, passwords, tokens) from queries sent to the service, but does not provide instructions for sanitizing or validating the content received from the service.
  • [DATA_EXFILTRATION]: The skill sends the user's full question to an external MCP tool to improve documentation relevance. Although it mandates redacting secrets first, this remains a data sharing mechanism where user context is transmitted to a non-whitelisted external service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — documentation-lookup