exa-similar-finder

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external web pages via the exa_find_similar tool, which presents an attack surface where malicious content could try to influence the agent.\n- Ingestion points: External URLs searched via exa_find_similar as noted in SKILL.md.\n- Boundary markers: There are no specific delimiters to isolate search results from the agent's instructions.\n- Capability inventory: The agent can interact with tools via sandbase_call_tool.\n- Sanitization: No content filtering or validation is specified for the search outputs.\n- Mitigation: The skill includes strong instructions to perform 'Read-only research only' and to 'Never take actions on platforms,' which effectively lowers the risk of exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — exa-similar-finder