context7-auto-research

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

From the provided README fragment there is no conclusive evidence of intentional malware, but multiple supply-chain and data-exfiltration risks exist: unverified transitive install via npx, missing endpoint/privacy details for the Context7 API, and an auto-trigger feature that can cause network requests using conversational context. Treat the package as medium risk until a repository-level code review confirms that endpoints are legitimate, requests are minimal and redacted as appropriate, TLS is enforced, secrets are not leaked or logged, and there are no post-install or native-binary behaviors. If you cannot perform that review, avoid installing the skill in sensitive environments or run it in a constrained sandbox with network controls.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:42 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcontext7-auto-research%2F@7f051ea5bdf9eeb9f3d18bd57120bc3fa4a3c270