exa-search

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to resolve script paths and perform searches. Specifically, Step 2 uses awk to parse .aris/installed-skills.txt and git to find the repository root. Step 3 and Step 6 execute python scripts (exa_search.py and research_wiki.py) with arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web via Exa search results, including highlights, full text, and metadata.
  • Ingestion points: Step 3 and Step 4 ingest content extraction from external URLs.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the processing flow.
  • Capability inventory: The skill has Bash(*), Read, and Write permissions, allowing it to execute scripts and write to the filesystem (research-wiki/).
  • Sanitization: There is no evidence of sanitization or escaping of the extracted web content before it is processed or used in subsequent steps.
  • [DYNAMIC_EXECUTION]: User-supplied arguments and data extracted from search results (titles, authors, venues) are interpolated into shell commands in Step 3 and Step 6 without explicit sanitization, creating a potential command injection surface.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the exa-py package from the official Python package registry (PyPI).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — exa-search