exa-similar-finder
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external web pages via the
exa_find_similartool, which presents an attack surface where malicious content could try to influence the agent.\n- Ingestion points: External URLs searched viaexa_find_similaras noted inSKILL.md.\n- Boundary markers: There are no specific delimiters to isolate search results from the agent's instructions.\n- Capability inventory: The agent can interact with tools viasandbase_call_tool.\n- Sanitization: No content filtering or validation is specified for the search outputs.\n- Mitigation: The skill includes strong instructions to perform 'Read-only research only' and to 'Never take actions on platforms,' which effectively lowers the risk of exploitation.
Audit Metadata