Back to skill

Security audit

Tavily Search

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Tavily web-search skill, with the main caveat that users should protect the Tavily API key and avoid sending sensitive queries to the external search service.

Install only if you intend to use Tavily as an external search provider. Treat TAVILY_API_KEY as a secret, avoid committing it to repositories or sharing it in logs, and do not include private data, credentials, or confidential business information in search queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables web searches through an external API but does not explicitly warn that user queries will be transmitted to Tavily. This creates a real privacy and data-handling risk because users may unknowingly send sensitive prompts, internal data, or secrets to a third party.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Most of the instructional content and examples are presented in Chinese, and the file does not indicate that the language is optional or region-specific. This can constitute a language policy issue because it effectively forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation tells users to place an API key in config or environment variables but gives no warning that the key is sensitive credential material. This can lead to accidental exposure through checked-in config files, shell history, logs, screenshots, or insecure local storage practices.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.