context7-cli

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Context7 CLI skill appears broadly aligned with its stated purpose of discovering, authenticating, installing, and generating AI coding skills across multiple assistants. The footprint—OAuth authentication, registry interactions, local skill directories, and generation workflows—fits a legitimate developer tooling use case. Security risks are present but moderate and largely manageable with standard best practices (secure token storage, user review before global installs, and content auditing of generated skills). Overall, the skill is BENIGN with MEDIUM risk considerations due to credential handling and potential exposure in logs or global installations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:17 PM
Package URL
pkg:socket/skills-sh/arisng%2Fgithub-copilot-fc%2Fcontext7-cli%2F@ca3421c6b07f5550af8b9c40e54bac7eef779908