exa-search

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends configuring the exa-mcp-server via npx. Exa is a well-known AI search service, and this is the official method for its MCP integration.\n- [PROMPT_INJECTION]: The skill enables the agent to fetch and process arbitrary web content, creating a surface for indirect prompt injection.\n
  • Ingestion points: Content retrieved from the web_search_exa and get_code_context_exa tools.\n
  • Boundary markers: No delimiters or instructions are provided to help the agent distinguish between search content and instructions.\n
  • Capability inventory: Agents in this environment typically have broad permissions, including command execution and file access.\n
  • Sanitization: No sanitization is performed on search results before they are processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:20 AM
Security Audit — agent-trust-hub — exa-search