tavily

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Tavily-based skill is coherent with its stated purpose: performing live web searches and content extraction via a defined API, with results formatted for AI consumption. The security footprint appears appropriate for a legitimate developer tooling scenario, relying on a single external API and an environment-provided API key. No evidence of autonomous real-world actions, credential harvesting, or supply-chain risk via unverifiable binaries is present. Monitor for logging of results and ensure API keys and content are handled with minimal exposure and proper access controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/mathews-tom%2Fpraxis-skills%2Ftavily%2F@8f1d5aed3b481fb85621237e5f02210034d490f8