context7

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to https://context7.com/api/v2 to retrieve documentation. These operations are consistent with the skill's stated purpose and target the vendor's official API domain.
  • [COMMAND_EXECUTION]: The skill uses curl and jq via a shell script (scripts/context7.sh) to perform API calls and parse JSON responses. User input for search queries and topics is properly handled using jq -sRr @uri to ensure it is safely URL-encoded before being interpolated into the API URL, preventing command or URL injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation retrieved from an API. While this presents an ingestion surface for untrusted data, the risk is mitigated as the skill primarily targets documentation from well-known libraries and frameworks. The impact is assessed as low given the nature of the data (documentation) and the absence of high-privilege capabilities associated with the ingested content.
  • [CREDENTIALS_SAFE]: The skill correctly instructs the user to store their API key in an environment variable (CONTEXT7_API_KEY) rather than hardcoding it in the script or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 06:43 AM