Back to skill

Security audit

Tavily AI Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tavily web-search integration with some credential-handling and dependency-installation cautions, but no hidden or purpose-mismatched behavior was found.

Install only if you are comfortable sending search terms and selected options to Tavily. Prefer storing the Tavily key in a protected config or environment variable, avoid passing real keys on the command line, and consider pinning `tavily-python` in an isolated environment before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:329
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tavily_search.py:124
Finding

Tavily API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 191)May include surrounding context.

python
args = parser.parse_args()
    
    # Get API key from args or environment
    api_key = args.api_key or os.getenv("TAVILY_API_KEY")
    
    result = search(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents use of environment-based secrets and API access but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, this can lead to overly broad implicit access, making it harder to enforce least privilege and increasing the chance the skill can access secrets or capabilities beyond what users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages sending arbitrary queries and optional raw-content extraction to Tavily, a third-party service, but does not clearly warn users that their prompts, domains, and possibly fetched page content leave the local environment. This creates a privacy and data-handling risk if users include sensitive, proprietary, or regulated information in searches or content extraction requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation shows multiple ways to provide the Tavily API key but does not explicitly treat it as sensitive credential material or warn against hardcoding, committing, logging, or exposing it in command history. This omission can lead to credential leakage, unauthorized API use, billing abuse, or account compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.