exa-fetch

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external websites which is a standard surface for indirect prompt injection.\n
  • Ingestion points: The web_fetch_exa tool returns content from arbitrary URLs provided at runtime.\n
  • Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between the fetched data and its core instructions.\n
  • Capability inventory: The agent is instructed to present information and answer questions based on the retrieved content.\n
  • Sanitization: The skill does not define any filtering or sanitization steps for the retrieved text within the instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 01:46 PM
Security Audit — agent-trust-hub — exa-fetch