tavily-web
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installation instructions recommend using
npx skills add -g BenedictKing/tavily-web, which downloads and executes code from a remote source on GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes content from external websites, creating a vulnerability where malicious instructions embedded in web pages could influence the agent's behavior.
- Ingestion points: External web search results and content extracted from URLs during crawling (SKILL.md).
- Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate external content from the agent's system instructions.
- Capability inventory: The skill provides the agent with capabilities to search the web, extract content, and crawl websites.
- Sanitization: There is no evidence in the skill instructions of sanitization, filtering, or validation performed on the ingested web content before it is processed by the model.
Audit Metadata