exa-search
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for the user to configure the Exa MCP server using
npx -y exa-mcp-server. This downloads and executes the official package for a well-known AI search service. - [INDIRECT_PROMPT_INJECTION]: The skill functions by retrieving data from the public web and code repositories through the
web_search_exaandget_code_context_exatools. This external, untrusted content is ingested into the agent's context, which is a standard surface for indirect prompt injection attacks where malicious instructions hidden in web pages could attempt to influence the agent's behavior. - Ingestion points: Web search results and code context retrieved from
web_search_exaandget_code_context_exa(SKILL.md). - Boundary markers: None specified in the instructions to separate search results from system prompts.
- Capability inventory: The skill defines tools for network-based search but does not contain internal scripts for file writing or subprocess execution beyond the documented MCP configuration.
- Sanitization: No explicit sanitization or filtering of the retrieved web content is described.
Audit Metadata