tavily-usage
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from the open web through search and extraction tools, creating a vulnerability surface where external content can influence agent behavior.
- Ingestion points: Web content retrieved via
mcp__tavily__tavily_searchandmcp__tavily__tavily-extract(SKILL.md). - Boundary markers: The instructions lack specific guidance on using delimiters or instructions to ignore embedded commands in the retrieved data.
- Capability inventory: The skill is intended to be used by an agent with broader capabilities (like shell or file access), which could be targeted by malicious instructions embedded in scraped websites.
- Sanitization: There is no mention of sanitizing, filtering, or validating the content extracted from external URLs before the agent processes it.
- [COMMAND_EXECUTION]: The skill documentation references a local script
tavily_extract_to_advanced.pydescribed as a hook that automatically modifies tool calls. Execution of local scripts represents a capability that should be monitored.
Audit Metadata