exa-search

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and retrieve content from arbitrary external web pages, which is a common surface for indirect prompt injection attacks.
  • Ingestion points: External content is ingested via exa.search_and_contents() and exa.get_contents() as shown in SKILL.md, references/contents.md, and references/sdk-patterns.md.
  • Boundary markers: The provided patterns do not explicitly demonstrate the use of secure delimiters or instructions to ignore embedded commands within the retrieved text.
  • Capability inventory: The skill facilitates the retrieval of full-page text, summaries, and highlights for processing by the agent.
  • Sanitization: There is no explicit evidence of sanitization or validation of the retrieved web content before it is presented to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:47 PM
Security Audit — agent-trust-hub — exa-search