exa-search

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process untrusted data from the open web.
  • Ingestion points: Raw search snippets from web_search_exa and full webpage content from web_fetch_exa (referenced in references/searching.md and references/extraction.md) are ingested into the agent context for analysis.
  • Boundary markers: The instructions in SKILL.md and references/extraction.md guide the agent to extract specific structured data into predefined schemas, which helps isolate relevant data from potential injection content, though explicit delimiters for raw content are not mandated.
  • Capability inventory: The skill uses web search and retrieval tools to gather data and synthesizes it into reports or structured files in the ./exa-results/ directory as described in SKILL.md.
  • Sanitization: Results are filtered and deduplicated based on relevance and quality criteria (defined in references/filtering.md and references/source-quality.md) before being presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:12 AM
Security Audit — agent-trust-hub — exa-search