Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This is a straightforward Tavily web-search integration skill with expected external API use and no evidence of hidden, destructive, or automatic behavior.
Install this only if you intend to use Tavily. Treat queries, URLs, and extracted or crawled page content as data shared with Tavily, avoid submitting sensitive or unauthorized targets, keep the API key in a secret manager or environment variable, and monitor usage for crawl and research workflows.
--- ## 1. Search API (`POST https://api.tavily.com/search`) | Parameter | Type | Required | Default | Allowed Values / Ranges | | :--- | :--- | :--- | :--- | :--- |
--- ## 2. Extract API (`POST https://api.tavily.com/extract`) Extracts raw content from specific URLs without executing a search.
--- ## 3. Crawl API (`POST https://api.tavily.com/crawl`) Traverses a website's link graph and extracts content.
--- ## 4. Map API (`POST https://api.tavily.com/map`) Quickly maps the URL topology of a target domain without extracting page content.
--- ## 5. Research API (`POST https://api.tavily.com/research`) Asynchronous deep research execution.
65/65 vendors flagged this skill as clean.