Back to plugin

Security audit

Tavily OpenClaw plugin

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tavily web search and extraction plugin whose network use is purpose-aligned, though users should avoid sending sensitive queries or private URLs to Tavily.

Before installing, understand that search queries and URLs submitted for extraction go to Tavily or any configured base URL. Do not include secrets, tokens, private internal links, or sensitive personal data unless you have approved that disclosure.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation does not warn users that search queries and submitted URLs are transmitted to the external Tavily service. This can cause users or downstream agents to send sensitive prompts, internal URLs, tokens, or private research targets to a third party without informed consent, creating a data disclosure and privacy risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.