skills/sehoon787/my-codex/exa-search/Gen Agent Trust Hub

exa-search

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the use of npx to fetch and run the exa-mcp-server package from the official npm registry.
  • [COMMAND_EXECUTION]: Includes instructions for the user to configure the MCP server in their local environment via shell-based configuration files.
  • [PROMPT_INJECTION]: As a search-based utility, the skill creates an interface for processing untrusted external data which is a standard surface for indirect prompt injection.
  • Ingestion points: Web and code search results processed from SKILL.md.
  • Boundary markers: Not present; the agent processes raw search results.
  • Capability inventory: Limited to retrieving and presenting search results as defined in the skill parameters.
  • Sanitization: Content is retrieved directly from the search engine without additional filtering instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:41 AM
Security Audit — agent-trust-hub — exa-search