Back to skill

Security audit

Tavily Best Practices

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Tavily integration skill; its external API use is expected, but users should avoid sending sensitive data through the examples.

Install this only if you intend to use Tavily or related LLM integrations. Use scoped API keys, keep real secrets out of sample code, and do not submit private URLs, credentials, regulated data, customer data, or proprietary documents unless your organization has approved that external processing and retention.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill documents sending search queries, URLs, and extracted content to Tavily but does not warn users that these inputs may contain sensitive data and will be transmitted to a third-party service. In an agent or coding-assistant context, users may paste internal URLs, proprietary prompts, or confidential research topics, so the omission creates a real privacy and data-handling risk even though the documentation itself is not overtly malicious.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The documentation describes agentic web research and automatic source gathering but does not clearly warn users that their prompts and embedded data may be sent to Tavily and third-party websites during searches. In a developer-facing skill, this omission can lead to accidental disclosure of sensitive internal information, credentials, customer data, or proprietary context when users copy production prompts into examples.

VirusTotal

No VirusTotal findings

View on VirusTotal