cli-anything-exa
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web through its
searchandcontentscommands. This creates a surface for indirect prompt injection where malicious instructions embedded in web pages could influence the agent's behavior. - Ingestion points: The
searchandcontentssubcommands inSKILL.mdare designed to bring external web data into the agent's context. - Boundary markers: The instructions do not define specific delimiters or warnings to treat search results as untrusted data.
- Capability inventory: The skill is primarily focused on search and content retrieval; however, the agent's overall capabilities (such as command execution) determine the potential impact.
- Sanitization: No explicit sanitization or filtering of the retrieved content is mentioned in the skill definition.
- [EXTERNAL_DOWNLOADS]: The skill instructions include a command to install the CLI directly from a GitHub repository hosted by the vendor.
- Evidence:
pip install git+https://github.com/HKUDS/CLI-Anything.git#subdirectory=exa/agent-harnessinSKILL.md.
Audit Metadata