exa-search
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and retrieve content from arbitrary external web pages, which is a common surface for indirect prompt injection attacks.
- Ingestion points: External content is ingested via
exa.search_and_contents()andexa.get_contents()as shown inSKILL.md,references/contents.md, andreferences/sdk-patterns.md. - Boundary markers: The provided patterns do not explicitly demonstrate the use of secure delimiters or instructions to ignore embedded commands within the retrieved text.
- Capability inventory: The skill facilitates the retrieval of full-page text, summaries, and highlights for processing by the agent.
- Sanitization: There is no explicit evidence of sanitization or validation of the retrieved web content before it is presented to the agent's context.
Audit Metadata