context7
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the
ctx7package globally usingnpm install -g ctx7@latestor to execute it directly vianpx ctx7@latest. This introduces a dependency on a third-party package from an external registry. - [COMMAND_EXECUTION]: The skill performs shell command execution by running
ctx7 libraryandctx7 docs. The arguments for these commands, including the library names and search queries, are derived from user-provided input. - [DATA_EXFILTRATION]: User-supplied technical queries are passed to the
ctx7CLI tool, which communicates with a remote service to fetch documentation. While the skill contains warnings for the agent to exclude sensitive credentials or proprietary code from queries, the transmission of data to an external provider is inherent to the tool's function. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process documentation and code examples from external sources. Maliciously crafted documentation could potentially contain instructions intended to override the agent's behavior (indirect prompt injection).
- Ingestion points: Technical documentation and code snippets retrieved via
ctx7 docs(SKILL.md). - Boundary markers: The skill uses section headers to structure flow but lacks explicit delimiters for the external content injected into the prompt context.
- Capability inventory: The skill has the capability to execute shell commands and perform network operations via the
ctx7CLI. - Sanitization: There is no explicit sanitization or filtering of the documentation content retrieved before it is presented to the agent.
Audit Metadata