by exa-labs
Exa MCP for web search and web crawling!
# Add to your Claude Code skills
git clone https://github.com/exa-labs/exa-mcp-serverGuides for using mcp servers skills like exa-mcp-server.
Last scanned: 4/20/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@mapbox/node-pre-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: Anthropic's MCP TypeScript SDK has a ReDoS vulnerability",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@tootallnate/once: @tootallnate/once vulnerable to Incorrect Control Flow Scoping",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@vercel/fun: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/gatsby-plugin-vercel-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/hydrogen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vercel/next: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/nft: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/redwood: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/remix-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/routing-utils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vercel/static-build: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vercel/static-config: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "axios: Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "debug: Regular Expression Denial of Service in debug",
"severity": "low"
},
{
"type": "npm-audit",
"message": "diff: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
"severity": "low"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "follow-redirects: follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mcp-handler: mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp outputs backtracking regular expressions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "semver: semver vulnerable to Regular Expression Denial of Service",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shelljs: Improper Privilege Management in shelljs",
"severity": "high"
},
{
"type": "npm-audit",
"message": "smol-toml: smol-toml: Denial of Service via TOML documents containing thousands of consecutive commented lines",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar: Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: Use of Insufficiently Random Values in undici",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vercel: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "whoami: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "yaml: yaml is vulnerable to Stack Overflow via deeply nested YAML collections",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-04-20T06:14:54.820Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}exa-mcp-server is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by exa-labs. Exa MCP for web search and web crawling!. It has 4,922 GitHub stars.
exa-mcp-server returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/exa-labs/exa-mcp-server" and add it to your Claude Code skills directory (see the Installation section above).
exa-mcp-server is primarily written in TypeScript. It is open-source under exa-labs on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh exa-mcp-server against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Connect to Exa's hosted MCP server:
https://mcp.exa.ai/mcp
Or use a plugin when your client supports one.
This repository is an Agent Plugin. Install it with any compatible client.
Install from the Claude Plugin Marketplace, or run:
claude plugin install exa@claude-plugins-official
Install via Plugins in ChatGPT, or run:
codex mcp add exa --url https://mcp.exa.ai/mcp
Most clients can be configured manually with the standard mcpServers shape:
{
"mcpServers": {
"exa": {
"type": "streamable-http",
"url": "https://mcp.exa.ai/mcp",
}
}
}
Exa MCP works with most other clients, point them at https://mcp.exa.ai/mcp.
| Client | Where to add it |
|---|---|
| Kiro | Use the Kiro power, or add manually to ~/.kiro/settings/mcp.json |
| LM Studio | Add to LM Studio, or add manually to mcp.json |
| Replit | Add to Replit |
| Grok Build | /marketplace → install Exa, then /mcp to sign in |
| Gemini CLI | Add manually to ~/.gemini/settings.json |
| OpenCode | Add manually to opencode.json |
| Windsurf | Add manually to ~/.codeium/windsurf/mcp_config.json |
| Google Antigravity | Add manually to mcp_config.json |
| Zed | Add manually to settings.json under context_servers |
| Warp | Settings → Agents → MCP servers |
| v0 by Vercel | Settings → MCP connections |
| Tool | Description |
|---|---|
web_search_exa |
Search the web for any topic and get clean, ready-to-use content |
web_fetch_exa |
Read a webpage's full content as clean markdown from one or more URLs |
tools parameter)| Tool | Description |
|---|---|
agent_run |
Run an Exa Agent for multi-step research, list-building, enrichment, and structured output |
web_search_advanced_exa |
Advanced search with filters, domains, dates, highlights, summaries, and subpage crawling |
Enable tools by appending them to the MCP URL (this will replace the defaults, so include all you want):
https://mcp.exa.ai/mcp?tools=web_search_advanced_exa
https://mcp.exa.ai/mcp?tools=web_search_exa,web_fetch_exa,agent_run
Exa Agent requires authentication (OAuth or an API key).
Skills live in skills/ and load with Agent Plugin / Claude plugin installs.
| Skill | Path | Use when |
|---|---|---|
search |
skills/search/ |
Deep research, lead gen, competitive analysis, multi-step web investigation |
exa-agent |
skills/exa-agent/ |
Exa Agent runs, enrichment, structured output, Connect providers |
Invoke from your client's skill UI (or /skill-name where supported). MCP-only setups still get the tools; skills add orchestration on top.
The hosted MCP server works anonymously with rate limits. For higher limits and access to Exa Agent, use either OAuth or an API key.
OAuth is preferred: most clients prompt you to sign in to Exa. To force the login flow (useful for shared connectors and plugins), use https://mcp.exa.ai/mcp?login or https://mcp.exa.ai/mcp/oauth.
If you prefer, you can get an API key from the dashboard and pass it on the URL as ?exaApiKey=…. You can also send it as a Authorization: Bearer … header or an x-api-key header.
Built with ❤️ by Exa