Back to skill

Security audit

mdgs-tavily-search-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Tavily web-search skill with expected external API use and no evidence of hidden persistence, exfiltration, or destructive behavior.

Install this only if you are comfortable using Tavily as a third-party service for search and page retrieval. Avoid sending confidential queries, private URLs, authenticated pages, or sensitive business data unless you have approval, and use crawl/map features only on targets you are authorized to access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
node scripts/tavily.js search "搜索内容" [--depth basic|advanced] [--max-results N]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
node scripts/tavily.js search "搜索内容" [--depth basic|advanced] [--max-results N]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
node scripts/tavily.js search "搜索内容" [--depth basic|advanced] [--max-results N]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
node scripts/tavily.js search "搜索内容" [--depth basic|advanced] [--max-results N]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
node scripts/tavily.js search "搜索内容" [--depth basic|advanced] [--max-results N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents use of environment variables for a sensitive API key and code execution capability, but it declares no explicit tool scope or permissions boundary. In an agent setting, missing scope metadata can cause the skill to be invoked without clear authorization controls, increasing the risk of unintended access to secrets or execution context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill whenever the user needs searching, webpage retrieval, scraping, site mapping, or research, which is broad enough to match many ordinary requests. Over-broad activation increases the chance the agent sends user queries or target URLs to an external service when a local answer or narrower tool would have been sufficient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill centers on external search, extraction, crawling, mapping, and research, but it does not warn that prompts, URLs, and retrieved content may be sent to or collected from third-party services. This can lead to unintentional disclosure of sensitive user data or analysis targets, especially in enterprise or confidential contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is written entirely in Chinese, which can impose a language/locale constraint on users without any stated opt-in or justification. The policy requires either offering a language choice or clearly documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains hard-coded Chinese output for errors and usage text, and the rest of the CLI messaging continues in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the tool is clearly documented as region-specific, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The document is primarily written in Chinese, but several example prompts and URLs are presented in English, such as 'Who is Leo Messi?' and 'What are the latest developments in AI?'. While not severe, this can imply a default language preference without explicitly stating that users may interact in their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The extract and crawl examples encourage collecting third-party page content without reminding users about authorization, terms-of-service, privacy, or sensitive-data handling. While the examples are ordinary documentation, they normalize data collection behavior that could be misused against sites or used on confidential URLs without proper review.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest is in scope for vague-trigger review, and the only natural-language description is a broad capability summary rather than a clearly bounded invocation condition or trigger scope. It does not specify when the skill should or should not be used, nor provide exclusion conditions or concrete trigger phrases.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Using a caret version range for @tavily/core allows automatic adoption of future minor or patch releases, which can introduce unintended behavior changes or, in the worst case, a compromised upstream package version. In a skill that performs web search and content retrieval, dependency compromise could affect network-facing behavior and data handling, increasing supply-chain risk.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"author": "",
  "license": "ISC",
  "dependencies": {
    "@tavily/core": "^0.7.2"
  }
}

Static analysis

No suspicious patterns detected.