tavily

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS rather than benign: the stated purpose matches Tavily search, and the official Tavily API/domain are legitimate, but the skill's real behavior hinges on an unseen local shell script that retrieves a raw API key from `pass`. There is no evidence of overt malware or third-party exfiltration in the provided text, yet the hidden script, credential exposure path, and broader-than-needed write capabilities make the footprint only partially verifiable.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:02 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Ftavily%2F@8789e41936b2df83045518fc0916dc37b98d70f9