exa-search

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the official exa-mcp-server package via npx, which is a standard procedure for integrating well-known MCP services.
  • [CREDENTIALS_UNSAFE]: Correctly instructs users to use environment variables for API keys instead of hardcoding them, utilizing standard placeholders.
  • [PROMPT_INJECTION]: The skill ingests untrusted external data from the web as its primary function. This constitutes a surface for indirect prompt injection, which is an inherent part of the skill's intended research purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — exa-search