tavily-research
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
tvlyCLI to perform research and analysis. Invocations are restricted to thetvlybinary as specified in the skill's tool configuration. - [INDIRECT_PROMPT_INJECTION]: The skill aggregates and processes information from external web sources, presenting a theoretical attack surface for indirect injection. * Ingestion points: External web content retrieved during the research process as described in
SKILL.md. * Boundary markers: The skill does not define specific delimiters to separate untrusted web content from the agent's instructions. * Capability inventory: The skill can executetvlyCLI commands and write structured research reports to the local file system using the-oor--outputflags. * Sanitization: There are no explicit sanitization or filtering steps defined in the skill instructions for content fetched from the web.
Audit Metadata