aisa-tavily-hardened
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose matches its capabilities, but it routes all search and extraction through AIsa's intermediary gateway instead of the official Tavily API. That third-party data flow and credential centralization are the main risks; scope is otherwise narrow and there is no evidence of malware or hidden installation behavior in the provided skill.
Confidence: 90%Severity: 52%
Audit Metadata