Atlas / MCP servers / exa-labs / exa-mcp-server

exa-mcp-serverSAFE

mcp/exa-labs/exa-mcp-server

Exa MCP for web search and web crawling!

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
9 7r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
5,089
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Exa MCP Server

Connect AI agents to Exa for web search, content fetching, and multi-step research.

Read from source at commit f614aae2c956OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add exa-mcp-server --env EXA_API_KEY=${EXA_API_KEY} --env EXA_API_KEY_BYPASS=${EXA_API_KEY_BYPASS} --env KV_REST_API_TOKEN=${KV_REST_API_TOKEN} --env OAUTH_AUDIENCE=${OAUTH_AUDIENCE} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "exa-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "EXA_API_KEY": "${EXA_API_KEY}",
        "EXA_API_KEY_BYPASS": "${EXA_API_KEY_BYPASS}",
        "KV_REST_API_TOKEN": "${KV_REST_API_TOKEN}",
        "OAUTH_AUDIENCE": "${OAUTH_AUDIENCE}"
      }
    }
  }
}
03

Exposed tools (9)

7 read · 2 write · 0 destructive.

ToolRiskDescription
agent_runwriteStart or resume an Exa Agent run; runs may take several minutes. Retain the returned run ID and resume with runId when the tool reports the run is still running. An interrupted tool call is not an explicit cancellation request.
company_research_exaread[Deprecated: Use web_search_advanced_exa instead] Research any company to get business information, news, and insights. Best for: Learning about a company
deep_researcher_checkread[Deprecated] Check status and get results from a deep research task. Best for: Getting the research report after calling deep_researcher_start. Returns: Research report when complete, or status update if still running. Important: Keep calling with the same research ID until status is
deep_researcher_startwrite
deep_search_exaread
get_code_context_exareadFind code examples, documentation, and programming solutions. Best for: Any programming question - API usage, library examples, code snippets, debugging help. Returns: Relevant code and documentation. Query tips: describe what you
linkedin_search_exaread⚠️ DEPRECATED: This tool is deprecated. Please use
people_search_exaread[Deprecated: Use web_search_advanced_exa instead] Find people and their professional profiles. Best for: Finding professionals, executives, or anyone with a public profile. Returns: Profile information and links.
web_search_advanced_exaread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vercelignore
.vercelignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/exaResponses.ts:2
import type { ExaContentsResponse, ExaSearchResponse } from "../../src/types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/api/mcp.test.ts:78
vi.mock("../../../src/mcp-handler.js", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/api/mcp.test.ts:82
vi.mock("../../../src/utils/auth.js", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/api/mcp.test.ts:112
const { handleRequest } = await import("../../../api/mcp.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/api/mcp.test.ts:776
const { handleOptions } = await import("../../../api/mcp.js");
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:13
<a href="https://chatgpt.com/plugins/exa?open_in_app"><img src="https://img.shields.io/badge/Codex%2FChatGPT_Plugin-4A5BFE?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/publish-mcp-registry.yml:52
sudo mv mcp-publisher /usr/local/bin/
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, agnost, exa-js, jose, mcp-handler, zod, @types/node, @upstash/ratelimit
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:132
If you prefer, you can get an API key from the [dashboard](https://dashboard.exa.ai/api-keys) and pass it on the URL as `?exaApiKey=...`. You can also send it as a `Authorization: Bearer ...` header o
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:128
The hosted MCP server works anonymously with rate limits. For higher limits and access to Exa Agent, use either OAuth or an API key.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f614aae2c956full audit observations/trust-audit/mcp-server/exa-labs__exa-mcp-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f614aae2c956SAFEB89first audit
06

Questions

What is the exa-mcp-server MCP server?

Exa MCP for web search and web crawling!

What tools does exa-mcp-server expose?

9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is exa-mcp-server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does exa-mcp-server need?

It reads EXA_API_KEY, EXA_API_KEY_BYPASS, KV_REST_API_TOKEN, OAUTH_AUDIENCE, OAUTH_ISSUER, OAUTH_USER_AGENTS, OPENAI_APPS_CHALLENGE_TOKEN, RATE_LIMIT_BYPASS and UPSTASH_REDIS_REST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does exa-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as exa-mcp-server at 3.4.2.

How current is this page?

The grade is for one exact copy of the source (f614aae2c956), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement