tavily-web

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instruction npx skills add -g BenedictKing/tavily-web downloads and installs code from a repository belonging to a third-party GitHub user, which is an unverifiable source.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is web search and content extraction, creating a surface for processing untrusted external data that may contain malicious instructions.
  • Ingestion points: The skill ingests data from external websites and search results via the Tavily API (SKILL.md).
  • Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the documentation.
  • Capability inventory: The skill performs network operations to crawl and search the web.
  • Sanitization: There is no indication of content filtering or sanitization of the retrieved web data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — tavily-web