Web Search
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is internally consistent: it runs a small Node script that sends search queries to Exa's MCP endpoint and returns results; there are no unrelated secrets, installs, or system access requested.
This skill appears to do what it claims: run the included Node script that sends your query to Exa's MCP endpoint and returns search snippets. Before installing or running it: 1) avoid sending passwords, API keys, or other sensitive data in queries since they will be transmitted to exa.ai; 2) note the publisher and homepage are unknown—if you need stronger assurance, review the search.mjs contents yourself (it's short) or run it in an isolated environment; 3) if you require guaranteed privacy, prefer using an enterprise/trusted search integration or a local search tool.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
