Back to skill

Security audit

Tavily Search Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Tavily web-search helper, but its install instructions fetch and run mutable remote code after asking the user to place an API key in the downloaded directory.

Install only if you trust the GitHub repository owner and are comfortable sending search queries to Tavily. Prefer using TAVILY_API_KEY from your environment rather than creating a plaintext apikey file, avoid searching for secrets or confidential material, and verify or pin the downloaded code before running ./search.sh.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:31
Finding

Execution of Unpinned Code Retrieved from a Remote Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–48
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
git clone https://github.com/JayeGT002/Tavily-Search-Skill.git tavily-search-skill
cd tavily-search-skill

The installation workflow later executes the remotely retrieved script:

bash
./search.sh "test"

Technical Analysis

The installation instructions clone the mutable default branch of a remote Git repository without specifying a reviewed commit hash or verifying a cryptographic signature or checksum. The workflow then executes search.sh from that repository.

Consequently, the code executed during installation is not necessarily the same code contained in the audited artifact. The effective payload can change after review if the upstream repository is modified. This creates a time-of-check-to-time-of-use supply-chain weakness and provides a direct remote code execution channel.

The workflow also instructs the user to create an apikey file before running the verification command. A malicious replacement for search.sh could therefore read and exfiltrate that credential when executed.

Attack Path

  1. An attacker compromises the upstream repository, its owner account, or another mechanism capable of changing its default branch.
  2. The attacker replaces or modifies search.sh with malicious shell commands.
  3. An agent follows the documented installation workflow and clones the current default branch without pinning a commit.
  4. The user supplies a Tavily API key, which is stored in the skill directory as apikey.
  5. The agent runs ./search.sh "test" as instructed.
  6. The modified script executes with the installing user's privileges and can access the API key and other resources available to that user.

Impact Assessment

Successful exploitation permits arbitrary command execution with the privileges ...[truncated 625 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installation to a specific, reviewed commit hash rather than cloning and executing the mutable default branch.
  2. Prefer signed, immutable releases and verify the maintainer's signature before using the downloaded content.
  3. Publish an expected cryptographic checksum for the release archive or entry script and verify it before execution.
  4. Inspect the checked-out commit and confirm that it matches the reviewed version before running any script.
  5. Create or expose the API key only after code verification, and avoid placing credentials in a directory controlled by newly downloaded code.
  6. Run the initial verification in a restricted environment with minimal filesystem access, a sanitized environment, and limited network permissions.
  7. Document an explicit trusted commit or release version in SKILL.md, for example:
bash
git clone https://github.com/JayeGT002/Tavily-Search-Skill.git tavily-search-skill
cd tavily-search-skill
git checkout --detach EXPECTED_REVIEWED_COMMIT
test "$(git rev-parse HEAD)" = "EXPECTED_REVIEWED_COMMIT" || exit 1

The expected commit should be independently authenticated; merely recording an attacker-controlled commit from the remote repository is insufficient.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior claims Tavily-backed web search, but the described implementation also includes local blocklist filtering and, per the finding, may not actually implement Tavily interaction at all. A capability mismatch is dangerous because it can mislead users and reviewers about what data is accessed, how results are produced, and whether content is being silently filtered or substituted.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to use shell commands, read local files, and perform network actions, but it does not declare any explicit tool scope or permissions boundaries. This weakens reviewability and containment, making it easier for the skill to be invoked with broader capabilities than users or platform policy may expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks the user to provide an API key and stores it in a local plaintext file, but provides no warning about secret handling, storage risks, or safer alternatives. Plaintext secrets can be exposed through backups, logs, accidental reads by other tools, repository mistakes, or weak host isolation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

bash
echo "USER_PROVIDED_API_KEY" > apikey
chmod 600 apikey

Step 4: Verify installation

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- `jq`

Install if missing:
- Ubuntu/Debian: `sudo apt-get install curl jq`
- macOS: `brew install curl jq`
- Alpine: `apk add curl jq`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON values in the "reason" field are written exclusively in Chinese, which imposes a specific language choice in the skill's natural-language content. The file does not provide any user language selection, fallback, or documented region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · search.sh (reported line 22)May include surrounding context.

sh
exit 1
fi

TAVILY_ENDPOINT="https://api.tavily.com/search"
TAVILY_USAGE_ENDPOINT="https://api.tavily.com/usage"

# ===== Parse args =====

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · search.sh (reported line 23)May include surrounding context.

sh
exit 1
fi

TAVILY_ENDPOINT="https://api.tavily.com/search"
TAVILY_USAGE_ENDPOINT="https://api.tavily.com/usage"

# ===== Parse args =====

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script makes an outbound POST request containing the user's search query and an authorization token to an external service. External transmission is intrinsic to a web-search skill, but it remains security-relevant because it can leak sensitive user input to a third party and creates dependence on remote service trustworthiness.

Content

Scanner excerpt · search.sh (reported line 54)May include surrounding context.

sh
include_images: ($ii == "true")
    }')

response=$(curl -s -w "\n%{http_code}" -X POST "$TAVILY_ENDPOINT" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $TAVILY_API_KEY" \
    -d "$json_payload")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User queries are sent to a third-party API, and returned data is pulled back into the agent flow without any disclosure or consent mechanism in the script. In a search skill this transmission is expected functionally, but it still creates a real privacy risk because sensitive prompts, internal identifiers, or confidential research terms may be exposed externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description says to use the skill when the user asks to "search the web / look up sources / find links," which are broad, everyday phrases and does not provide exclusion conditions or clearer trigger constraints. This can lead to unintended activation when a user mentions those phrases in a context where this specific skill is not desired.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions hardcode the user-facing API-key request in Chinese, which imposes a language choice without user opt-in. This is a natural-language policy issue because the skill does not offer locale selection or justify why Chinese is required.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script reads credentials from a local apikey file in addition to the environment, which introduces an undeclared secret-loading behavior and increases the chance of insecure key storage on disk. This is dangerous because local plaintext key files are easier to leak through file permissions, backups, or accidental inclusion in repositories.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script performs an additional authenticated request to Tavily's usage endpoint that is not necessary to fulfill the declared web-search function. While not overtly malicious, this expands external data access and account metadata exposure beyond user expectations, increasing privacy and transparency risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.