context7-auto-research
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions guide users to install implementation code from a community GitHub repository (BenedictKing/context7-auto-research) which is not a verified vendor.
- [PROMPT_INJECTION]: The skill retrieves documentation from an external API, creating a surface for indirect prompt injection where malicious instructions could be embedded in the documentation content.
- Ingestion points: External content fetched from Context7 API.
- Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the manifest.
- Capability inventory: The skill performs network requests to external endpoints.
- Sanitization: No sanitization or content validation mechanisms are described in the provided documentation.
Audit Metadata