tavily-2

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill documentation describes a legitimate-looking integration with the Tavily search API. The requested credential (TAVILY_API_KEY) and network access to tavily.com are appropriate for the stated purpose. Primary risks are standard supply-chain and network exposure from installing the 'tavily-python' package and sending queries/API key to an external service. Examples that pipe or follow URLs (curl/xargs) are user-driven patterns that can cause additional network calls and should be used with caution. No obfuscated code, hardcoded secrets, download-and-execute instructions, credential harvesting, or third-party intermediary routing are present in the provided document. To finalize trust decisions, review the actual scripts (scripts/tavily_search.py) and the tavily-python package source before use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Ftavily-2%2F@94514292cc9d496d65fad189219b955af14344b8