tavily-web

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (web search, extraction, crawling via Tavily) is coherent with its described capabilities. However, there is a notable security risk due to the use of an unverifiable installation source (npx BenedictKing/tavily-web), which triggers supply-chain concerns and warrants at least a high risk rating. Credential handling via environment variables is standard practice but requires careful handling to avoid leakage. Overall, the footprint is suspicious rather than clearly malicious, with a recommended stance toward upgrading to an officially verifiable distribution mechanism or including rigorous code provenance checks before use.

Confidence: 65%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Ftavily-web%2F@4f62180fb533b181071bc03e597e207f54570e03