ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      Whiteknight07

      Safety Report

      Exa Web Search (Free)

      @Whiteknight07

      Free AI search via Exa MCP. Web search for news/info, code search for docs/examples from GitHub/StackOverflow, company research for business intel. No API key needed.

      14,540Downloads
      94Installs
      47Stars
      2Versions
      API Integration4,971Search & Retrieval2,116Documentation1,163Git & Version Control784

      Security Analysis

      medium confidence
      Suspicious0.12 risk

      The skill is coherent in offering web/code/company search via a third‑party MCP service, but the runtime instructions require an external mcporter CLI and will send arbitrary queries to https://mcp.exa.ai — a potential data‑leak/privacy risk — and the registry metadata and SKILL.md disagree about required binaries.

      Feb 11, 20262 files5 concerns
      Purpose & Capabilityconcern

      The skill's stated purpose (web/code/company search via Exa MCP) matches the instructions which call a remote MCP service. However SKILL.md metadata declares a required binary 'mcporter' while the registry's top-level requirements list 'none' for required binaries — an inconsistency. Requesting mcporter is reasonable for this purpose, but the registry should declare it.

      Instruction Scopeconcern

      Runtime instructions tell the agent to run mcporter commands that configure and call a remote endpoint (https://mcp.exa.ai/mcp) and to enable optional tools (crawling, people search, deep researcher). Those commands will transmit user queries (and any data included in them) to an external service. The instructions do not limit or warn about sending sensitive data, nor do they require any local validation of results. Crawling and people-search features can retrieve or expose PII and arbitrary web content.

      Install Mechanismnote

      No install spec or code files are provided (instruction-only), so nothing is written to disk by the skill itself. Risk arises from reliance on an external binary (mcporter) and network calls to the MCP endpoint rather than from an installation step. The skill references GitHub/npm resources for Exa MCP which are plausible but unverified here.

      Credentialsnote

      The skill declares no required environment variables or credentials, which is consistent with 'No API key needed.' However, because queries are sent to a third party, this design means user prompts and any embedded secrets could be leaked to that external service. No provision is made to prevent accidental transmission of sensitive data.

      Persistence & Privilegenote

      always:false (normal). The skill can be invoked autonomously (platform default). Combined with the optional 'deep_researcher' and crawling/people-search tools, autonomous invocation increases the amount of data that could be sent externally if allowed — but autonomous invocation alone is not unusual.

      Guidance

      Before installing, consider: (1) The skill expects you to have the mcporter CLI and will configure and call a remote service (mcp.exa.ai). Verify you trust that domain and the mcporter binary (inspect its source or installed package). (2) Do not send secrets or private data in queries — the skill will forward whatever you ask to an external service. (3) The registry metadata omitted the required 'mcporter' binary — ask the publisher to correct this. (4) If you need stricter control, only enable the skill as user‑invocable (avoid autonomous runs), and test with non‑sensitive queries first. (5) If you require assurance, review the referenced GitHub/npm projects (exa-mcp-server) and any privacy/security docs for mcp.exa.ai before using.

      Latest Release

      v1.0.1

      Condensed skill: shorter description (171 chars vs 357), more concise SKILL.md (2.4KB vs 4.5KB). Core functionality unchanged.

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @Whiteknight07 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]