Exa Web Search Nodeskai

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This appears to be a straightforward web-search connector, but it sends queries to Exa's remote MCP service and optional advanced tools broaden what the agent can ask that service to do.

This skill is reasonable for web and code search if you trust mcporter and Exa's MCP service. Treat anything you search for as data shared with an external provider, and only enable the advanced Exa tools when you specifically need crawling, people search, or remote research-agent features.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Search terms, URLs, company names, and similar research inputs may be shared with the external Exa MCP service.

Why it was flagged

The skill configures a remote MCP service, so search requests made through the skill are sent outside the local environment to Exa.

Skill content
mcporter config add exa https://mcp.exa.ai/mcp
Recommendation

Avoid putting private, confidential, or sensitive personal information into search queries unless you are comfortable sending it to Exa.

What this means

If enabled, the agent can ask the remote service to perform broader research actions, including extracting page contents or researching professional profiles.

Why it was flagged

The optional configuration expands the tool surface from basic search to crawling, people search, and starting/checking remote research tasks.

Skill content
Six additional tools available by updating config URL: ... `crawling_exa` - Full page extraction ... `people_search_exa` - Professional profiles ... `deep_researcher_start/check` - AI research agent
Recommendation

Enable the advanced tool URL only if you need those functions, and review/approve uses that involve people searches, page crawling, or long-running research tasks.