mcp-context7-docs
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is benign, and the final data destination appears to be the official Context7 MCP endpoint, but the install path is inconsistent with the publisher and relies on an unverified third-party CLI installed via curl-to-shell. That supply-chain mismatch is disproportionate to a simple documentation lookup skill.
Confidence: 91%Severity: 84%
Audit Metadata