tavily-web

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a Tavily-based web research skill, and the Tavily API key requirement is proportionate, but the skill is distributed as a third-party transitive skill install from an unverified community source and processes untrusted web content that could indirectly influence an agent with broader permissions. With no confirmed malicious data exfiltration or mismatched credential scope, this is not confirmed malware, but it carries medium security risk.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:23 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ftavily-web%2F@24c20de3210efd67aec46836969fa518df44a9f5