exa-deep-search
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it is designed to ingest and process content from arbitrary public web sources.
- Ingestion points: External web data is brought into the agent's context through the
exa_searchandexa_contentstools as described inSKILL.mdandreferences/sandbase-api-map.md. - Boundary markers: The instructions do not define clear delimiters or include specific guidance for the agent to ignore instructions or commands embedded within the retrieved search results or extracted text.
- Capability inventory: The skill uses the
sandbase_call_toolto execute search and extraction operations. - Sanitization: The skill does not implement or mention sanitization, filtering, or validation of the content retrieved from external sources before presenting it to the agent for synthesis.
Audit Metadata