Irene Tavily Search

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Tavily web-search helper that sends user-provided searches to Tavily using a configured Tavily API key.

Install only if you are comfortable sending search terms to Tavily. Use a dedicated Tavily API key, keep .env files private, monitor quota usage, and avoid submitting confidential or regulated search terms unless Tavily handling is acceptable for your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The script sends user queries and the Tavily API key to an external third-party service without any explicit runtime notice, confirmation, or privacy guardrails. In an agent-skill context, users may assume local processing, so sensitive prompts or internal research terms could be unintentionally disclosed to an outside provider.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal