skills/dwsy/agent/tavily-search-free/Gen Agent Trust Hub

tavily-search-free

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill correctly manages sensitive information by reading the TAVILY_API_KEY from a .env file rather than hardcoding it in the source code.
  • [SAFE]: External dependencies like tavily-python and python-dotenv are official and standard packages for the skill's stated purpose of performing web searches and managing configurations.
  • [SAFE]: The skill's primary function is to retrieve external web content via the Tavily API. While this introduces a surface for indirect prompt injection, it is the intended behavior of a search utility, and the implementation does not include any dangerous local capabilities (such as arbitrary command execution) that could be triggered by this external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 09:13 AM
Security Audit — agent-trust-hub — tavily-search-free