tavily-search

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for the agent to ingest untrusted data from the public internet, creating an attack surface for indirect prompt injection.
  • Ingestion points: Results from tavily_search and the full-text content retrieved via tavily_extract are directly incorporated into the agent's context in SKILL.md.
  • Boundary markers: The skill does not provide instructions to wrap or delimit search results with safety markers that would prevent the agent from executing instructions hidden in web content.
  • Capability inventory: The agent is granted tools to perform web research and deep extraction of arbitrary URLs.
  • Sanitization: There is no mention of filtering, sanitizing, or validating the content retrieved from external sources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:17 AM