exa-researcher
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation section directs users to execute
npx clawhub@latest, which downloads and executes code from an unverified external source not associated with the declared vendor or any trusted organizations. - [NO_CODE]: The skill contains no executable scripts or logic in the provided files. However, there is a discrepancy between the expected vendor (Demerzels-lab) and the metadata owner (sy2ruto) and repository (spooky-may), which could indicate a deceptive origin or impersonation.
- [PROMPT_INJECTION]: As a research tool utilizing Exa AI, the skill is designed to ingest and process data from external web sources, which is a known attack surface for indirect prompt injection. Ingestion points: External content retrieved via Exa AI tools. Boundary markers: None present in the skill instructions. Capability inventory: Research and data retrieval tools. Sanitization: Not specified in the provided instructions.
Audit Metadata