context7-auto-research
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the trust model is weak: a community skill is installed transitively from a personal GitHub repo, then may receive an API key and execute local repo code. No confirmed malicious behavior is shown, but the install path and credential forwarding are disproportionate enough to warrant caution.
Confidence: 82%Severity: 74%
Audit Metadata