exa-search

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct users to install code from a third-party repository (BenedictKing/exa-search) that is not identified as a pre-verified source.
  • [INDIRECT_PROMPT_INJECTION]: As a tool designed for semantic search and content discovery, the skill creates a surface for indirect prompt injection by ingesting untrusted data from the web.
  • Ingestion points: External web content and research data retrieved through the Exa API as described in SKILL.md.
  • Boundary markers: The skill documentation does not provide specific instructions for the agent to use delimiters or ignore instructions embedded in the search results.
  • Capability inventory: The skill utilizes network capabilities to fetch data which is then processed within the agent's context.
  • Sanitization: No information is provided regarding how the skill or agent validates or sanitizes the retrieved content before use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — exa-search