exa-search

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web searches and URL extractions which may contain adversarial instructions.
  • Ingestion points: External web content fetched in scripts/exa_search.py and scripts/exa_extract.py.
  • Boundary markers: Fetched content is structured in JSON output files, but the agent processes the raw extracted text.
  • Capability inventory: The skill can perform network operations via the Exa API and write content to local JSON files.
  • Sanitization: There is no explicit sanitization of the retrieved text to filter out embedded prompt instructions.
  • [EXTERNAL_DOWNLOADS]: Fetches search results and content from Exa's official API endpoints using the exa-py Python SDK.
  • [REMOTE_CODE_EXECUTION]: Uses the uv package manager to run scripts with the required exa-py dependency as specified in the skill's setup instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — exa-search