Mcp Skill

PassAudited by ClawScan on May 1, 2026.

Overview

The skill is a small instruction-only wrapper for an external Exa MCP search and research service, with no artifact evidence of malicious behavior.

This appears coherent and purpose-aligned for web and research workflows. Before installing, be aware that it relies on an external MCP service; avoid sending secrets, credentials, private code, or confidential research material unless you trust that provider.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Search queries, URLs, company names, LinkedIn lookups, or code-context text you provide for these tools may be sent to the external MCP service.

Why it was flagged

The skill is explicitly built around an external MCP provider. That is purpose-aligned, but it means research prompts and other user-supplied inputs for these tools may be handled by that provider.

Skill content
This skill wraps the MCP at https://mcp.exa.ai/mcp for various tools such as web search, deep research, and more.
Recommendation

Use it for non-sensitive research tasks and avoid sending secrets, private code, credentials, or confidential business data unless you trust the external provider and its data handling.

What this means

You have limited registry-level context for who maintains this wrapper and where to verify it.

Why it was flagged

The skill has limited provenance metadata. There is no local code or install script in the provided artifacts, so this is not evidence of malicious behavior, but it gives users less information to verify the publisher or project.

Skill content
Source: unknown; Homepage: none
Recommendation

Install only if you are comfortable with the listed publisher and the disclosed Exa MCP endpoint.