Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- tests.mjs:12
Security audit
Security checks across malware telemetry and agentic risk
This skill is a small, disclosed Tavily web-search wrapper that sends user-provided search queries to Tavily using an environment API key.
Install only if you are comfortable sending search queries to Tavily and spending Tavily API credits. Avoid using it for secrets, confidential incident text, client identifiers, or private internal strategy unless you explicitly approve that disclosure.
64/64 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal