tavily-hikari-best-practices
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose is plausible, but it relies on an unverified `tvly-hikari` CLI and instructs users to provide Hikari tokens to it while routing traffic through custom hosts not matched to Tavily's documented public API. With no verified same-org source or install trail for the binary, this is a high supply-chain and credential-forwarding risk.
Confidence: 87%Severity: 84%
Audit Metadata