exa-deep-search

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it is designed to ingest and process content from arbitrary public web sources.
  • Ingestion points: External web data is brought into the agent's context through the exa_search and exa_contents tools as described in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: The instructions do not define clear delimiters or include specific guidance for the agent to ignore instructions or commands embedded within the retrieved search results or extracted text.
  • Capability inventory: The skill uses the sandbase_call_tool to execute search and extraction operations.
  • Sanitization: The skill does not implement or mention sanitization, filtering, or validation of the content retrieved from external sources before presenting it to the agent for synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — exa-deep-search