context7-auto-research

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS] (MEDIUM): The installation instructions recommend using npx skills add -g BenedictKing/context7-auto-research. This command downloads and installs code from a personal GitHub repository that is not part of the defined trusted organizations or repositories list. This could lead to the execution of unverified scripts.
  • [PROMPT_INJECTION] (LOW): The skill's primary function is to fetch documentation via the Context7 API. This creates an Indirect Prompt Injection surface (Category 8).
  • Ingestion points: External documentation fetched via Context7 API.
  • Boundary markers: None specified in the documentation.
  • Capability inventory: Performs network requests to fetch external content.
  • Sanitization: No sanitization or validation mechanisms are described for the fetched content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 06:39 PM