context7-auto-research

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions guide users to install implementation code from a community GitHub repository (BenedictKing/context7-auto-research) which is not a verified vendor.
  • [PROMPT_INJECTION]: The skill retrieves documentation from an external API, creating a surface for indirect prompt injection where malicious instructions could be embedded in the documentation content.
  • Ingestion points: External content fetched from Context7 API.
  • Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the manifest.
  • Capability inventory: The skill performs network requests to external endpoints.
  • Sanitization: No sanitization or content validation mechanisms are described in the provided documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 06:14 PM