Skip to content
Back to skills

Doc Lookup

ASecurity

Unified documentation lookup for Bug Hunter agents. Uses Context Hub (chub) as primary source with Context7 API fallback. Provides verified library/framework documentation to prevent false positives and ensure correct fix patterns.

  • 17 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 2, 2026
ai-agentsbashsqlnodeexpressapidocumentation

Works with

  • api

Security analysis

A100/100

Scanned September 2, 2026

npx -y skills add CarlosCaPe/octorato --skill doc-lookup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Doc Lookup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Doc Lookup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/carloscape-doc-lookup/badge)](https://www.skillsdirectory.com/skills/carloscape-doc-lookup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: doc-lookup
description: "Unified documentation lookup for Bug Hunter agents. Uses Context Hub (chub) as primary source with Context7 API fallback. Provides verified library/framework documentation to prevent false positives and ensure correct fix patterns."
---

# Doc Lookup — Verified Documentation Access

## Documentation Lookup (Context Hub + Context7 fallback)

When you need to verify a claim about how a library, framework, or API actually behaves — do NOT guess from training data. Look it up.

### When to use this

- "This framework includes X protection by default" — verify it
- "This ORM parameterizes queries automatically" — verify it
- "This function validates input" — verify it
- "The docs say to do X" — verify it
- Any claim about library behavior that affects your bug verdict

### How to use it

`SKILL_DIR` is injected by the orchestrator. Use it for all helper script paths.

The lookup script tries **Context Hub (chub)** first for curated, versioned docs, then falls back to **Context7** when chub doesn't have the library.

**Step 1: Search for the library**
```bash
node "$SKILL_DIR/scripts/doc-lookup.cjs" search "<library>" "<what you need to know>"
```
Example: `node "$SKILL_DIR/scripts/doc-lookup.cjs" search "prisma" "SQL injection parameterized queries"`

This returns results from both sources with a `recommended_source` and `recommended_id`.

**Step 2: Fetch documentation**
```bash
node "$SKILL_DIR/scripts/doc-lookup.cjs" get "<library-or-id>" "<specific question>"
```
Example: `node "$SKILL_DIR/scripts/doc-lookup.cjs" get "prisma/orm" "are raw queries parameterized by default"`

This fetches curated docs from chub if available, otherwise Context7 documentation snippets with code examples.

**Optional flags:**
- `--lang js|py` — language variant (for chub docs with multiple languages)
- `--source chub|context7` — force a specific source

### Rules

- Only look up docs when you have a SPECIFIC claim to verify. Do not speculatively fetch docs for every library in the codebase.
- One lookup per claim. Don't chain 5 searches — pick the most impactful one.
- If the API fails or returns nothing useful, say so explicitly: "Could not verify from docs — proceeding based on code analysis."
- Cite what you found: "Per Express docs: [quote]" or "Prisma docs confirm that $queryRaw uses parameterized queries."

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…