exa-fetch
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external websites which is a standard surface for indirect prompt injection.\n
- Ingestion points: The
web_fetch_exatool returns content from arbitrary URLs provided at runtime.\n - Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between the fetched data and its core instructions.\n
- Capability inventory: The agent is instructed to present information and answer questions based on the retrieved content.\n
- Sanitization: The skill does not define any filtering or sanitization steps for the retrieved text within the instruction set.
Audit Metadata