exa-researcher

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation section directs users to execute npx clawhub@latest, which downloads and executes code from an unverified external source not associated with the declared vendor or any trusted organizations.
  • [NO_CODE]: The skill contains no executable scripts or logic in the provided files. However, there is a discrepancy between the expected vendor (Demerzels-lab) and the metadata owner (sy2ruto) and repository (spooky-may), which could indicate a deceptive origin or impersonation.
  • [PROMPT_INJECTION]: As a research tool utilizing Exa AI, the skill is designed to ingest and process data from external web sources, which is a known attack surface for indirect prompt injection. Ingestion points: External content retrieved via Exa AI tools. Boundary markers: None present in the skill instructions. Capability inventory: Research and data retrieval tools. Sanitization: Not specified in the provided instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 01:00 AM
Security Audit — agent-trust-hub — exa-researcher