Exa PoolSAFE
A lightweight MCP server that encapsulates the Exa Pool API as a toolkit for AI assistants to call.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
轻量的 MCP Server,将 Exa Pool API 封装为可供 AI 助手调用的工具集。
安装与配置
1. 下载
下载 exa_pool_mcp.py 到本地:
# 下载到 ~/.claude/ 目录(推荐) curl -o ~/.claude/exa_pool_mcp.py https://raw.githubusercontent.com/TullyMonster/exa-pool-mcp/main/exa_pool_mcp.py # 或克隆整个仓库 git clone https://github.com/TullyMonster/exa-pool-mcp.git && cd exa-pool-mcp
2. 配置
以 Claude Code 为例:
claude mcp add --transport stdio exa-pool --env EXA_POOL_BASE_URL=... --env EXA_POOL_API_KEY=... -- uv run ~/.claude/exa_pool_mcp.py
重启 Claude Code 以应用 MCP 的配置变更。
❤️ 致谢与参考
若需高使用限额或商业用途,请考虑使用 Exa 官方 API。
dc45bdc86449OBSERVED · 2026-10-08Exposed tools (6)
5 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
exa_answer | read | |
exa_create_research | write | |
exa_find_similar | read | |
exa_get_contents | read | |
exa_get_research | read | |
exa_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
dc45bdc86449full audit observations/trust-audit/mcp-server/tullymonster__exa-pool.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | dc45bdc86449 | SAFE | B | 89 | first audit |
Questions
What is the Exa Pool MCP server?
A lightweight MCP server that encapsulates the Exa Pool API as a toolkit for AI assistants to call.
What tools does Exa Pool expose?
6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Exa Pool safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Exa Pool need?
It reads EXA_POOL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Exa Pool run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (dc45bdc86449), read on 2026-10-08. The repository is watched and re-audited when it changes.