mcp-context7
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve and process external library documentation, which introduces a surface for indirect prompt injection from untrusted web content. However, as the skill provides only instructional context without executable scripts, it is considered safe.
- Ingestion points: External documentation retrieved via Context7 MCP tools (referenced in SKILL.md).
- Boundary markers: Absent.
- Capability inventory: None; the skill does not include any executable code or scripts (SKILL.md).
- Sanitization: Absent.
Audit Metadata