← 返回 Skills 市场
47
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install mcp-skill-hardened
功能描述
Wraps the Exa MCP server (mcp.exa.ai) for web search, deep research, and related tools.
安全使用建议
This skill appears coherent and low-risk as delivered (instruction-only, no installs, no credentials). Before installing: 1) Verify the skill's origin (source/homepage is missing) so you know who authored it. 2) Confirm whether your environment needs to supply Exa MCP credentials or network access — the SKILL.md mentions mcp.exa.ai but does not declare credentials. 3) Test it in a restricted/sandboxed agent to observe actual network calls and ensure it doesn't leak sensitive prompts. 4) Observe the guardrails in SKILL.md (they're sensible) and require per-request consent for any long-running 'deep_researcher_start' operations. If you need higher assurance about provenance, request a published source or upstream repository before deployment.
功能分析
Type: OpenClaw Skill
Name: mcp-skill-hardened
Version: 1.0.0
The skill bundle is a security-hardened wrapper for the Exa MCP search service. It includes explicit defensive instructions in SKILL.md and SAFETY.md designed to prevent SSRF, bulk resource exhaustion, and corporate espionage. No malicious logic, data exfiltration, or harmful prompt injections were found; the content is focused on enforcing safety guardrails for the AI agent.
能力评估
Purpose & Capability
The name and description claim to wrap Exa's MCP for web search and research; the SKILL.md enumerates matching tools (web_search_exa, deep_search_exa, crawling_exa, company_research_exa, etc.). There are no unrelated required binaries, environment variables, or config paths requested, so the required surface matches the stated purpose. (The source/homepage are missing, which reduces provenance but does not create an internal inconsistency.)
Instruction Scope
SKILL.md is instruction-only and directs the agent to use the listed MCP tools. It includes explicit security guardrails (SSRF handling, bulk-enumeration limits, refusal for corporate espionage, per-request consent for deep research). It does not instruct the agent to read arbitrary local files, system credentials, or to exfiltrate data to unexpected endpoints.
Install Mechanism
There is no install spec and no code files to write to disk; this is the lowest-risk pattern (instruction-only). No downloads, package installs, or custom binaries are specified.
Credentials
The skill declares no required environment variables, credentials, or config paths, which is proportional to an instruction-only wrapper. One caveat: the SKILL.md references an external endpoint (https://mcp.exa.ai/mcp); any real integration may require API credentials or network access that are not declared here — the lack of declared credentials is consistent with an instruction-only skill but means you should verify any runtime wiring before enabling it in a production agent.
Persistence & Privilege
The skill does not request always:true and does not declare system-wide configuration changes. It is user-invocable and allows normal autonomous invocation (platform default) but does not demand elevated persistent privileges.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install mcp-skill-hardened - 安装完成后,直接呼叫该 Skill 的名称或使用
/mcp-skill-hardened触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of mcp-skill-hardened, wrapping Exa MCP for research and search tools.
- Provides an interface to MCP at mcp.exa.ai for web search, deep research, and related capabilities.
- Includes tools: web_search_exa, web_search_advanced_exa, get_code_context_exa, deep_search_exa, crawling_exa, company_research_exa, linkedin_search_exa, deep_researcher_start, deep_researcher_check.
- Applies four security guardrails, including client-side URL validation, batching limits, anti-espionage controls, and user consent requirements for deep research.
- Outlines which tools require explicit user confirmation and which do not.
元数据
常见问题
Mcp Skill Hardened 是什么?
Wraps the Exa MCP server (mcp.exa.ai) for web search, deep research, and related tools. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 47 次。
如何安装 Mcp Skill Hardened?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install mcp-skill-hardened」即可一键安装,无需额外配置。
Mcp Skill Hardened 是免费的吗?
是的,Mcp Skill Hardened 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Mcp Skill Hardened 支持哪些平台?
Mcp Skill Hardened 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Mcp Skill Hardened?
由 Faberlens(@snazar-faberlens)开发并维护,当前版本 v1.0.0。
推荐 Skills