context7-auto-research

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The provided SKILL metadata and README describe a plausible documentation-fetching integration that requests an optional API key and is installed via 'npx skills add'. There is no direct evidence in this fragment of active malicious code (no hardcoded secrets, no remote exfiltration endpoints listed, no obfuscated payloads). However, the distribution/install mechanism (npx installation of a third-party skill), absence of explicit network endpoints, potential for transitive dependency installation, and auto-trigger capability raise meaningful supply-chain and credential risks. Without the actual implementation (source code, dependency lockfile, and the exact endpoints used), this skill should be treated as medium risk: acceptable with caution only if consumers review the installed code, pin versions, audit dependencies, and restrict API keys or run it in a constrained environment.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/baotoq%2Fmicro-commerce%2Fcontext7-auto-research%2F@f2ad37976fb65db0eed83a38b3be25cdcf55d323