exa-search

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for the user to configure the Exa MCP server using npx -y exa-mcp-server. This downloads and executes the official package for a well-known AI search service.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by retrieving data from the public web and code repositories through the web_search_exa and get_code_context_exa tools. This external, untrusted content is ingested into the agent's context, which is a standard surface for indirect prompt injection attacks where malicious instructions hidden in web pages could attempt to influence the agent's behavior.
  • Ingestion points: Web search results and code context retrieved from web_search_exa and get_code_context_exa (SKILL.md).
  • Boundary markers: None specified in the instructions to separate search results from system prompts.
  • Capability inventory: The skill defines tools for network-based search but does not contain internal scripts for file writing or subprocess execution beyond the documented MCP configuration.
  • Sanitization: No explicit sanitization or filtering of the retrieved web content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — exa-search