build-with-exa

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown documentation files designed to guide an AI agent in using the Exa API. No executable scripts, binaries, or active code components are provided within the skill directory.
  • [NO_CODE]: The skill package contains documentation and instructional markdown files only, with no bundled scripts or binary assets.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing standard, well-known software libraries including 'exa-py', 'exa-js', 'openai', and 'requests'. These references target official package registries and repositories maintained by the vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes how to ingest data from the live web via search results. It provides clear boundaries and recommendations to constrain the content and structure of data retrieved, mitigating risks associated with untrusted external content.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs users to manage sensitive API keys via environment variables and uses obvious placeholders in examples, following security best practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:47 PM
Security Audit — agent-trust-hub — build-with-exa