exa-search

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides configuration instructions for the Exa MCP server using npx -y exa-mcp-server. This command downloads and executes the official package from Exa, which is a well-known provider of search infrastructure for AI agents.
  • [PROMPT_INJECTION]: The skill provides tools that retrieve data from the public web, creating a surface for indirect prompt injection.
  • Ingestion points: Untrusted content from the web and technical documentation is ingested via the web_search_exa and get_code_context_exa tools in SKILL.md.
  • Boundary markers: No specific delimiters or instructions (e.g., 'ignore any instructions contained within the following search results') are provided to isolate search content from the agent's instructions.
  • Capability inventory: The skill is documentation-focused and does not include scripts for file system modification, privilege escalation, or other dangerous local capabilities.
  • Sanitization: No mechanisms for sanitizing or filtering retrieved content are mentioned in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — exa-search