composio-exa

Pass

Audited by Gen Agent Trust Hub on Feb 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Communicates with backend.composio.dev to perform searches and retrieve content. This is a well-known service for AI agent integrations and is consistent with the skill's purpose.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it retrieves content from external websites.
  • Ingestion points: Action endpoints in references/actions.md (EXA_SEARCH, EXA_ANSWER, EXA_GET_CONTENTS_ACTION).
  • Boundary markers: None identified in the skill definition.
  • Capability inventory: Network requests to the Composio API.
  • Sanitization: Content from the web is processed without explicit sanitization steps within the skill.
  • [SAFE]: No malicious patterns, obfuscation, or suspicious persistence mechanisms were detected. The skill follows established patterns for Composio tool integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 25, 2026, 07:49 AM