context7-auto-research

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the trust model is weak: a community skill is installed transitively from a personal GitHub repo, then may receive an API key and execute local repo code. No confirmed malicious behavior is shown, but the install path and credential forwarding are disproportionate enough to warrant caution.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:15 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fcontext7-auto-research%2F@a1e5ef227d08b214d32bdd266207806e79b61fb1