exa-contents

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a guide for interacting with the Exa AI API (api.exa.ai). All network operations described are standard API calls to the vendor's own domain, intended for content extraction and analysis.
  • [DATA_EXFILTRATION]: Authentication examples utilize an environment variable ($EXA_API_KEY) rather than hardcoded secrets, which aligns with security best practices for credential management.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process content from external URLs. While this represents a surface for indirect prompt injection, it is the primary intended function of the tool. The instructions do not contain any patterns attempting to bypass safety filters or override agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 04:01 AM
Security Audit — agent-trust-hub — exa-contents