tavily
Fail
Audited by Socket on Feb 28, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This is documentation for a Tavily search integration (skill) and contains no executable or obfuscated malicious code. The described capabilities (search, AI answers, raw content extraction, images) are consistent with the stated purpose and require a Tavily API key, which is appropriate. The primary security considerations are operational: users should protect their API keys, be cautious when enabling raw HTML extraction or piping results into shell commands (which can fetch arbitrary external URLs), and avoid executing downstream commands on untrusted data. Overall risk is low but the raw-content and chaining examples slightly increase the attack surface.
Confidence: 95%Severity: 90%
Audit Metadata