javascript-pro
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to fetch and process external documentation and examples via the Context7 MCP. This creates an attack surface for tool output poisoning (Category 8c), where malicious instructions embedded in third-party library documentation could influence the agent's code generation or command execution. There are no explicit instructions for content sanitization or the use of boundary markers for the ingested data.
Audit Metadata