tavily-remote-mcp
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a Tavily-access wrapper, but its actual data flow is through a third-party DeepNLP/OneKey gateway rather than official Tavily APIs. That proxy design and credential routing are disproportionate trust assumptions for a Tavily-branded skill, though there is no clear evidence of outright malware or hidden payloads.
Confidence: 88%Severity: 71%
Audit Metadata