context7

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the ctx7 package from the official NPM registry. This occurs either via global installation (npm install -g ctx7@latest) or at runtime through npx.
  • [REMOTE_CODE_EXECUTION]: Executes code from the ctx7 package using npx ctx7@latest <command>. This pattern involves downloading and running remote executable content from a third-party package.
  • [COMMAND_EXECUTION]: Invokes shell commands like ctx7 library <name> <query> and ctx7 docs <libraryId> <query>. These commands directly incorporate user-supplied input as parameters, which could lead to command injection vulnerabilities if the input is not sanitized before being passed to the shell.
  • [CREDENTIALS_UNSAFE]: Instructs users to manage authentication through the CONTEXT7_API_KEY environment variable or the ctx7 login command. While environment variables are a standard practice for secret management, users should ensure the ctx7 tool is trustworthy before providing or storing API keys.
  • [PROMPT_INJECTION]: The skill processes user-supplied queries through a CLI tool that has shell execution capabilities. This represents an indirect prompt injection surface where a malicious user query could attempt to manipulate the CLI parameters or exploit shell command structures.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — context7