documentation-lookup

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits user queries to the external Context7 MCP service to resolve library IDs and fetch documentation. This is the primary and intended function of the skill. To protect user privacy, the instructions include a specific 'Best Practice' to redact API keys, passwords, and tokens before sending queries to the tool.
  • [PROMPT_INJECTION]: The skill handles data from an external documentation source. While this represents a surface for indirect prompt injection, it is managed by the skill's structured lookup workflow. 1. Ingestion points: Documentation snippets provided by the query-docs tool. 2. Boundary markers: Not specified for the returned content. 3. Capability inventory: The skill is limited to documentation lookup and lacks dangerous capabilities like file system access, network egress to arbitrary domains, or code execution. 4. Sanitization: The skill mandates redaction of secrets for outgoing data, although no explicit sanitization is defined for incoming documentation content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 10:46 PM