setup-context7-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the README documentation from the official Upstash Context7 repository on GitHub to guide the setup process.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied arguments and project metadata to perform documentation searches and update configuration files, creating a standard data processing attack surface. Ingestion points: User-supplied $ARGUMENTS and project technology descriptions in SKILL.md. Boundary markers: No explicit delimiters or instructions are used to separate input data from instructions. Capability inventory: The skill performs file system writes to CLAUDE.md files and uses network tools to search for documentation. Sanitization: Input data is not explicitly sanitized or validated before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — setup-context7-mcp