Back to skill

Security audit

Tavily

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tavily web-search skill that discloses its third-party API use, but users should treat all queries and URLs as leaving their environment.

Install only if you are comfortable sending search queries, target URLs, research prompts, and Tavily account usage requests to Tavily. Keep TAVILY_API_KEY in environment or a secrets manager, avoid submitting secrets, personal data, or internal-only URLs, and consider disabling or explicitly validating redirects before using the bundled helper in stricter environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tavily.py:27
Finding

Bearer Credential May Be Disclosed Before Redirect Validation

Content
View full analysis
Dict[str, str]: # Only read the single intended credential from the environment. api_key = _environ.get("TAVILY_API_KEY") if not api_key: _die("TAVILY_API_KEY environment variable not set") return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", "User-Agent": "hermes-skill-tavily/1.0", } def _try_parse_json(raw: bytes) -> Dict[str, Any]: text = raw.decode("utf-8", errors="replace") try: parsed = json.loads(text) except Exception: return {"raw": text} if isinstance(parsed, dict): return parsed return {"value": parsed} def _request(method: str, path: str, *, json_body: Optional[dict] = None, http_timeout: float = 60.0) -> Dict[str, Any]: # Hardcode the API host to prevent exfil via injected base URL overrides. url = f"{TAVILY_API_BASE_URL}{path}" headers = _headers() data = None if json_body is not None: headers = dict(headers) headers["Content-Type"] = "application/json" data = json.dumps(json_body).encode("utf-8") req = urllib.request.Request(url, data=data, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=http_timeout) as resp: final_url = resp.geturl() if not final_url.startswith(TAVILY_API_BASE_URL + "/"): _die(f"Unexpected redirect: {final_url}", code=1) raw = resp.read() except urllib.error.HTTPError as e: raw = e.read() payload = _try_parse_json(raw) _die(f"HTTP {e.code}: {payload}", code=1) except urllib.error.URLError as e: _die(f"Request failed: {e.reason}", code=1) except Exception as e: _die(f"Request failed: {type ...[truncated 2525 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
`SKILL_DIR` is the directory containing this `SKILL.md` file.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill performs network operations and documents outbound access to api.tavily.com, but it does not declare an explicit tool scope such as permissions or allowed-tools. That weakens policy enforcement and reviewability because an orchestrator cannot easily constrain or validate the skill's intended capabilities from metadata alone.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

No-Script Option (curl)

Use Tavily directly via curl (same endpoints, no bundled script):

bash
curl -s "https://api.tavily.com/search" \

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/bp-search.md (reported line 54)May include surrounding context.

md
### Fast + Ultra-Fast

| Depth        | When to use                                                                                                                                                             |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `ultra-fast` | When latency is absolutely crucial. Delivers near-instant results, prioritizing speed over relevance. Ideal for real-time applications where response time is critical. |
| `fast`       | When latency is more important than relevance, but you want results in reranked chunks format. Good for applications that need quick, targeted snippets.                |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes sending user-provided URLs and optional query text to Tavily's external extraction service but does not warn about privacy, data handling, or the risk of transmitting sensitive internal URLs or user prompts off-platform. In an agent skill, this can lead to unintended disclosure of private browsing targets, internal endpoints, or sensitive query context if users or upstream agents are not clearly informed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The file explicitly defines an external API endpoint, meaning skill inputs and extracted content are transmitted to a remote third-party service. While external network use is expected for this capability, it still creates a real data exfiltration surface if the skill is invoked with sensitive URLs, internal resources, or confidential query text.

Content

Scanner excerpt · references/extract.md (reported line 23)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation encourages real-time streaming of research progress, tool calls, search queries, and discovered sources, but does not warn that this data is sent to and surfaced by an external third-party API. In practice, users may include sensitive prompts, internal investigation topics, proprietary queries, or source URLs, and the streaming interface increases the likelihood that such metadata is exposed to external systems or UI logs without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to submit arbitrary research queries to a third-party service but does not warn that prompts and related data will be transmitted off-platform. In an agent skill context, users may include sensitive internal data in research requests, so the absence of disclosure and handling guidance creates a real privacy and data-governance risk even if the API itself is legitimate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

This skill is explicitly configured to send data to https://api.tavily.com/, which is an external network destination. External transmission is expected for a web-research integration, but in the absence of explicit trust boundaries, privacy warnings, or data-minimization guidance, it can expose sensitive prompts, queries, or embedded secrets to a third-party provider.

Content

Scanner excerpt · references/research.md (reported line 23)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill sends user-supplied search queries to Tavily's external API and can also request include_raw_content, which causes third-party retrieval and return of webpage content, yet the documentation shown here contains no explicit privacy, consent, or data-sharing warning. In an agent setting, users may provide sensitive prompts or identifiers, so silent transmission to an external provider creates a real confidentiality and compliance risk even though it is expected functionality for a search integration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The documented endpoint https://api.tavily.com/ is an external service, so use of this skill inherently transmits prompt-derived data outside the local trust boundary. While external connectivity is necessary for a web-search skill, it still represents a true security concern if the agent can forward sensitive inputs or fetched content without strict controls, especially because bearer-authenticated requests may expose organizational activity patterns to a third party.

Content

Scanner excerpt · references/search.md (reported line 23)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/research-get.md (reported line 23)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/usage.md (reported line 23)May include surrounding context.

md
optimized for LLMs.
  version: 1.0.0
servers:
  - url: https://api.tavily.com/
security: []
tags:
  - name: Search

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file documents a Research endpoint at /research/{request_id}, but the OpenAPI info.description says the REST API provides access to Tavily Search and Tavily Extract only. That documentation text contradicts the actual endpoint content in this file by excluding the Research capability being defined.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This Python code sends potentially sensitive user-provided data to an external API via POST requests in the search, extract, and research commands. While the module docstring says it calls Tavily APIs, there is no confirmation prompt or explicit user-facing disclosure near these operations about transmitting input data off-system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.