Search
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill appears to do what it says (call Tavily's search API) but its metadata omits the required API key and it assumes tools not declared in the registry (jq), so the packaging is inconsistent and needs clarification before install.
This skill legitimately calls Tavily's search API and requires a Tavily API key, but the registry metadata incorrectly lists no required environment variables. Before installing: (1) verify you trust Tavily and are comfortable sending search queries (and optionally page content) to a third-party API; (2) confirm where and how you want to store the TAVILY_API_KEY (SKILL.md suggests ~/.claude/settings.json) and be aware that this writes a persistent credential to disk; (3) ensure your environment has jq available (the script uses jq but the skill doesn't declare it); and (4) consider asking the publisher to update the registry metadata to declare TAVILY_API_KEY as a required credential so the packaging matches runtime behavior. If you do not trust Tavily or do not want to store credentials in agent settings, do not install.
Static analysis
Static analysis findings are pending for this release.
VirusTotal
No VirusTotal findings for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
