tavily
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Tavily-based skill is coherent with its stated purpose: performing live web searches and content extraction via a defined API, with results formatted for AI consumption. The security footprint appears appropriate for a legitimate developer tooling scenario, relying on a single external API and an environment-provided API key. No evidence of autonomous real-world actions, credential harvesting, or supply-chain risk via unverifiable binaries is present. Monitor for logging of results and ensure API keys and content are handled with minimal exposure and proper access controls.
Confidence: 98%
Audit Metadata