exa-search
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web searches and URL extractions which may contain adversarial instructions.
- Ingestion points: External web content fetched in scripts/exa_search.py and scripts/exa_extract.py.
- Boundary markers: Fetched content is structured in JSON output files, but the agent processes the raw extracted text.
- Capability inventory: The skill can perform network operations via the Exa API and write content to local JSON files.
- Sanitization: There is no explicit sanitization of the retrieved text to filter out embedded prompt instructions.
- [EXTERNAL_DOWNLOADS]: Fetches search results and content from Exa's official API endpoints using the exa-py Python SDK.
- [REMOTE_CODE_EXECUTION]: Uses the uv package manager to run scripts with the required exa-py dependency as specified in the skill's setup instructions.
Audit Metadata