skills/felipeangeli/skills/context7/Gen Agent Trust Hub

context7

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the ctx7 package globally using npm install -g ctx7@latest or to execute it directly via npx ctx7@latest. This introduces a dependency on a third-party package from an external registry.
  • [COMMAND_EXECUTION]: The skill performs shell command execution by running ctx7 library and ctx7 docs. The arguments for these commands, including the library names and search queries, are derived from user-provided input.
  • [DATA_EXFILTRATION]: User-supplied technical queries are passed to the ctx7 CLI tool, which communicates with a remote service to fetch documentation. While the skill contains warnings for the agent to exclude sensitive credentials or proprietary code from queries, the transmission of data to an external provider is inherent to the tool's function.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process documentation and code examples from external sources. Maliciously crafted documentation could potentially contain instructions intended to override the agent's behavior (indirect prompt injection).
  • Ingestion points: Technical documentation and code snippets retrieved via ctx7 docs (SKILL.md).
  • Boundary markers: The skill uses section headers to structure flow but lacks explicit delimiters for the external content injected into the prompt context.
  • Capability inventory: The skill has the capability to execute shell commands and perform network operations via the ctx7 CLI.
  • Sanitization: There is no explicit sanitization or filtering of the documentation content retrieved before it is presented to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — context7