exa-install-auth

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is narrow and the permissions are mostly proportionate, but the install instructions are internally inconsistent with Exa's current official docs. The main risk is supply-chain misdirection: the skill tells the agent to install package names that do not match the publisher's documented SDKs, then store an API key for use with them. There is no direct exfiltration or malware behavior shown, but the wrong-package + credential setup combination makes this unsafe to trust as-is.

Confidence: 93%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fexa-install-auth%2F@889eebd85f695bf2dc0052d70bd1bab7592674f8