exa-search

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions that download content from a third-party GitHub repository (BenedictKing/exa-search) which is not identified as a trusted source or vendor resource for googyosoo.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of retrieving and processing external search results.
  • Ingestion points: Data retrieved from external web sources via the Exa API (SKILL.md).
  • Boundary markers: There are no markers or instructions defined in the skill documentation to distinguish between retrieved content and agent instructions.
  • Capability inventory: The skill provides semantic search and discovery capabilities.
  • Sanitization: The documentation does not describe any sanitization or validation of the retrieved external data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — exa-search