exa-web-search-free

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest itself is not an embedded malware payload, but it instructs the client to route user queries to a third-party MCP endpoint, creating a meaningful supply-chain and privacy risk. The lack of safeguards and the availability of sensitive advanced tools (people search, long-running research agents) increase the potential for data exposure. Treat this as a privacy/supply-chain risk: audit mcporter client behavior and the MCP operator before use and do not send sensitive secrets or proprietary data through this service.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fexa-web-search-free%2F@82c822d39379b89e1a00641d706c0fa01099c9c4