T08 · Insecure Dependencies
- Location
SKILL.md:329- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Tavily web-search integration with some credential-handling and dependency-installation cautions, but no hidden or purpose-mismatched behavior was found.
Install only if you are comfortable sending search terms and selected options to Tavily. Prefer storing the Tavily key in a protected config or environment variable, avoid passing real keys on the command line, and consider pinning `tavily-python` in an isolated environment before use.
SKILL.md:329Unpinned Third-Party Dependency Installation
scripts/tavily_search.py:124Tavily API Key Can Be Exposed Through Command-Line Arguments
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
args = parser.parse_args()
# Get API key from args or environment
api_key = args.api_key or os.getenv("TAVILY_API_KEY")
result = search(
The skill documents use of environment-based secrets and API access but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, this can lead to overly broad implicit access, making it harder to enforce least privilege and increasing the chance the skill can access secrets or capabilities beyond what users expect.
The skill encourages sending arbitrary queries and optional raw-content extraction to Tavily, a third-party service, but does not clearly warn users that their prompts, domains, and possibly fetched page content leave the local environment. This creates a privacy and data-handling risk if users include sensitive, proprietary, or regulated information in searches or content extraction requests.
The documentation shows multiple ways to provide the Tavily API key but does not explicitly treat it as sensitive credential material or warn against hardcoding, committing, logging, or exposing it in command history. This omission can lead to credential leakage, unauthorized API use, billing abuse, or account compromise.
No suspicious patterns detected.