CtrlK
BlogDocsLog inGet started
Tessl Logo

tdg-personal/exa-search

Neural search via Exa MCP for web, code, and company research. Use when the user needs web search, code examples, company intel, people lookup, or AI-powered deep research with Exa's neural search engine.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Low

Low-risk findings.

2 low severity findings. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

The SKILL.md explicitly describes tools (web_search_exa and get_code_context_exa) that perform live web searches and fetch content from public sites (e.g., GitHub, Stack Overflow, LinkedIn, and arbitrary web pages) which the agent is expected to read and use to drive research and follow-up actions, exposing it to untrusted third-party content that could inject instructions.

Where we found it

exa.ai

domain · 5 sites

The plugin's tools (web_search_exa, get_code_context_exa) perform live web searches via the Exa API at exa.ai, fetching and ingesting arbitrary third-party web content (from GitHub, Stack Overflow, LinkedIn, and any public site) that the agent then reads and acts on, creating an indirect prompt-injection surface.

SKILL.md

32

Get an API key at [exa.ai](https://exa.ai).

SKILL.md

27

"args": ["-y", "exa-mcp-server"],

SKILL.md

38

### web_search_exa

SKILL.md

55

### get_code_context_exa

SKILL.md

56

Find code examples and documentation from GitHub, Stack Overflow, and docs sites.

Report incorrect finding
Low

W012: Unverifiable external dependency detected (runtime URL that controls agent).

What this means

The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.

Why it was flagged

The skill's MCP requirement runs "npx exa-mcp-server" at runtime, which fetches and executes remote npm package code (and points to https://exa.ai for the API key), so the exa-mcp-server package is a required external runtime dependency that executes remote code and can control agent behavior.

Where we found it

exa-mcp-server

dependency · 1 site

The plugin requires running `npx -y exa-mcp-server` at runtime, which fetches and executes the exa-mcp-server npm package from the npm registry without version pinning.

SKILL.md

27

"args": ["-y", "exa-mcp-server"],

Audited
Security analysis
Snyk