context7
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent, and routing queries plus an API key to Context7 is proportionate, but the skill uses an unreviewed local Python wrapper and explicitly tells the agent not to inspect it. No clear malicious exfiltration is shown, yet execution trust is weaker than the official same-org Context7 clients.
Confidence: 85%Severity: 63%
Audit Metadata