exa
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose is coherent, but its implementation relies on a third-party personal `api2cli` tool to generate and handle the Exa CLI and credentials. Official Bun installation only partly mitigates risk; the unpinned third-party CLI generation and credential forwarding make the overall security posture medium-high risk.
Confidence: 87%Severity: 82%
Audit Metadata