exa-rag

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the development of RAG pipelines that fetch external web content via Exa.ai and interpolate it into LLM prompts. This architecture is susceptible to indirect prompt injection attacks where content from retrieved websites could contain hidden instructions designed to override the agent's behavior.
  • Ingestion points: External data enters the agent context through search results in references/langchain.md (via ExaSearchRetriever), references/llamaindex.md (via ExaReader), and references/vercel-ai.md (via exa.searchAndContents).
  • Boundary markers: The provided prompt templates in references/langchain.md and references/llamaindex.md do not implement robust delimiters or instructions to treat fetched content as untrusted data.
  • Capability inventory: The skill demonstrates capabilities for network operations (Exa API) and tool execution (LangChain/CrewAI agents), which could be targets for manipulation via injected content.
  • Sanitization: The examples provided for processing search results do not include sanitization or filtering to remove potential injection patterns from the retrieved text.
  • [EXTERNAL_DOWNLOADS]: The documentation guides users to install various third-party packages from official registries to support the skill's functionality. This includes both Python (pip) and Node.js (npm) dependencies such as langchain-exa, llama-index-readers-web, crewai, @anthropic/mcp-exa, and ai.
  • [DATA_EXFILTRATION]: The skill performs outbound network operations to the Exa.ai API (https://api.exa.ai/v1) to retrieve search results. This is a legitimate and documented feature required for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:47 PM
Security Audit — agent-trust-hub — exa-rag