context7

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The overall purpose is legitimate and network flow targets the official Context7 service, but the skill is not fully coherent with a low-risk docs helper because it instructs secret-file discovery from hidden .env files and uses an undocumented local Python wrapper whose provenance is unclear. Main risk is credential handling and local wrapper trust, not confirmed malware.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:41 PM
Package URL
pkg:socket/skills-sh/am-will%2Fcodex-skills%2Fcontext7%2F@f3564f334efc9c8b40009d8694499d2115abe174