Tavily MCP Server for AI-Powered Web Search and Extraction

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and execute the tavily-mcp package from the official NPM registry. This is a standard and expected deployment method for the official MCP server provided by Tavily.
  • [SAFE]: The skill does not contain any hardcoded credentials, obfuscation, or unauthorized file access. All external references point to well-known technology domains (GitHub, NPM, Tavily).
  • [SAFE]: Although the skill enables processing of untrusted data from the web (via search and extraction), this is the primary purpose of the tool. Standard agent-side safety guardrails for handling web content are sufficient.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 10:10 AM
Security Audit — agent-trust-hub — Tavily MCP Server for AI-Powered Web Search and Extraction