Back to skill

Security audit

Tavily Web Search

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Tavily web-search skill that uses a Tavily API key and sends search queries to Tavily, which matches its stated purpose.

Install this only if you are comfortable sending search queries, options, and a Tavily API key to Tavily. Avoid putting secrets or proprietary text in search queries, and note that the environment-variable fallback appears to have a reliability bug if no secret file exists.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.py (reported line 40)May include surrounding context.

python
- images: List of image URLs (if requested)
    """
    
    # Get API key from secrets or environment
    api_key = None
    # Try multiple possible paths
    possible_paths = [

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents executable behavior that uses both network access and environment/secret access, but it does not declare any tool scope such as permissions or allowed-tools. This creates a governance gap: an agent may invoke the skill without clear authorization boundaries, and the documented secret path (workspace/secrets/tavily_api_key) increases the sensitivity because the skill is designed to read credentials and send data to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code accesses a credential from a secrets file or environment variable, which is a safety-relevant operation under the warning rules for code files. Although the docstring explains search behavior, there is no confirmation, visible log/print, or warning that the script reads authentication material from local secrets storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill sends user-provided search queries and options to a third-party web service without any explicit disclosure at execution time. In an agent setting, users may unknowingly include sensitive prompts, internal project names, or proprietary data in queries, causing unintended external data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This duplicate finding points to the same external POST request that sends user-controlled data to Tavily. In the context of an agent skill, such transmission can unintentionally leak sensitive operational or user data if the query is not screened or the user is not informed.

Content

Scanner excerpt · scripts/search.py (reported line 78)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            "https://api.tavily.com/search",
            json=payload,
            timeout=30

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This duplicate finding points to the same external POST request that sends user-controlled data to Tavily. In the context of an agent skill, such transmission can unintentionally leak sensitive operational or user data if the query is not screened or the user is not informed.

Content

Scanner excerpt · scripts/search.py (reported line 78)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            "https://api.tavily.com/search",
            json=payload,
            timeout=30

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The hardcoded Tavily API endpoint confirms this skill communicates with an external third-party service. That is expected behavior for a web-search integration, but it is still security-relevant because it creates a clear outbound channel for user-supplied content.

Content

Scanner excerpt · scripts/search.py (reported line 79)May include surrounding context.

python
try:
        response = requests.post(
            "https://api.tavily.com/search",
            json=payload,
            timeout=30
        )