exa-search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to resolve script paths and perform searches. Specifically, Step 2 uses
awkto parse.aris/installed-skills.txtandgitto find the repository root. Step 3 and Step 6 execute python scripts (exa_search.pyandresearch_wiki.py) with arguments. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web via Exa search results, including highlights, full text, and metadata.
- Ingestion points: Step 3 and Step 4 ingest content extraction from external URLs.
- Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the processing flow.
- Capability inventory: The skill has
Bash(*),Read, andWritepermissions, allowing it to execute scripts and write to the filesystem (research-wiki/). - Sanitization: There is no evidence of sanitization or escaping of the extracted web content before it is processed or used in subsequent steps.
- [DYNAMIC_EXECUTION]: User-supplied arguments and data extracted from search results (titles, authors, venues) are interpolated into shell commands in Step 3 and Step 6 without explicit sanitization, creating a potential command injection surface.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
exa-pypackage from the official Python package registry (PyPI).
Audit Metadata