tavily-web

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installation instructions recommend using npx skills add -g BenedictKing/tavily-web, which downloads and executes code from a remote source on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes content from external websites, creating a vulnerability where malicious instructions embedded in web pages could influence the agent's behavior.
  • Ingestion points: External web search results and content extracted from URLs during crawling (SKILL.md).
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate external content from the agent's system instructions.
  • Capability inventory: The skill provides the agent with capabilities to search the web, extract content, and crawl websites.
  • Sanitization: There is no evidence in the skill instructions of sanitization, filtering, or validation performed on the ingested web content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — tavily-web