context7
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to
https://context7.com/api/v2to retrieve documentation. These operations are consistent with the skill's stated purpose and target the vendor's official API domain. - [COMMAND_EXECUTION]: The skill uses
curlandjqvia a shell script (scripts/context7.sh) to perform API calls and parse JSON responses. User input for search queries and topics is properly handled usingjq -sRr @urito ensure it is safely URL-encoded before being interpolated into the API URL, preventing command or URL injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation retrieved from an API. While this presents an ingestion surface for untrusted data, the risk is mitigated as the skill primarily targets documentation from well-known libraries and frameworks. The impact is assessed as low given the nature of the data (documentation) and the absence of high-privilege capabilities associated with the ingested content.
- [CREDENTIALS_SAFE]: The skill correctly instructs the user to store their API key in an environment variable (
CONTEXT7_API_KEY) rather than hardcoding it in the script or instructions.
Audit Metadata