Back to skill

Security audit

context7-cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it asks agents to run mutable external CLI code, sometimes outside the sandbox, and includes commands that can change global agent configuration and installed skills.

Install only if you are comfortable with Context7 CLI network calls and agent-configuration changes. Prefer a pinned, reviewed ctx7 version, avoid sending secrets or proprietary code in doc queries, and review any setup, --global, --all, --yes, login, install, or remove command before running it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are overly broad, including generic 'how do I' questions about libraries and many common programming scenarios. In a skill that instructs external CLI usage and out-of-sandbox network access, over-triggering increases the chance the agent will invoke unnecessary third-party tooling, expanding attack surface and causing unsafe or irrelevant command execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to execute npx ctx7 without a pinned version, which allows whatever package is currently published under that name to be fetched and executed at runtime. Even though other examples use @latest, that is still unpinned and can introduce malicious or breaking upstream changes into the agent workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This reference uses npx ctx7 without an exact version, creating a supply-chain risk because npx will resolve and execute the current package version from the registry. In an agent skill, this is more dangerous because the document is prescribing operational behavior that may be followed automatically or with reduced scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command example at this line invokes npx ctx7 without version pinning, allowing registry-side changes to alter executed code over time. Because this skill is specifically about fetching external documentation and configuring tooling, it normalizes repeated network execution of mutable code, increasing exposure to compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This version-specific docs example still relies on an unpinned npx ctx7 executable, so while the library ID is pinned to a docs version, the CLI itself is not. An attacker controlling or compromising the package publication path could execute arbitrary code before any documentation lookup occurs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The docs lookup command is shown with npx ctx7 and no exact version, making the command susceptible to package substitution or malicious updates. In the context of an agent skill, unsafe examples can propagate into repeated automated use across many sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The login instruction uses npx ctx7@latest, which is still mutable and therefore not safely pinned. Combining authentication steps with execution of latest-tagged code is particularly risky because it may expose tokens or session state to compromised package code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The quota-error recovery guidance again directs users to run npx ctx7@latest login, which executes mutable code at the point users are likely to be troubleshooting and less cautious. Although not obviously malicious, it reinforces insecure operational practice and can lead to credential theft if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 11)May include surrounding context.

bash
ctx7 setup                     # Interactive — prompts for mode, then agent/install target
ctx7 setup --mcp               # Skip prompt, use MCP server mode
ctx7 setup --cli               # Skip prompt, use CLI + Skills mode

# MCP mode — target a specific agent

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 12)May include surrounding context.

bash
ctx7 setup                     # Interactive — prompts for mode, then agent/install target
ctx7 setup --mcp               # Skip prompt, use MCP server mode
ctx7 setup --cli               # Skip prompt, use CLI + Skills mode

# MCP mode — target a specific agent

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 26)May include surrounding context.

ctx7 setup --cli --antigravity # Antigravity (~/.config/agent/skills)

ctx7 setup --project # Configure current project instead of globally ctx7 setup --yes # Skip confirmation prompts

text

**Authentication options:**

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown documents --global installation, which writes into the user's home-directory skill locations, but it does not explicitly warn that the change affects all projects for that IDE target. Similar global scope is also shown for removal later, making the operational impact broader than project-local actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Remove section says 'Uninstall a skill by name' and gives deletion commands, but it does not explicitly disclose that installed files will be removed from project or global skill directories. For a destructive operation, a clear warning helps users understand the impact before running the command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.