tavily-hikari-cli

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for a managed Hikari deployment, but it routes Tavily activity and credentials through a non-official intermediary and requires an unverifiable wrapper CLI. That makes the main risk credential forwarding and full request visibility by third-party code/service, not confirmed malware.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Jul 15, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/IvanLi-CN%2Ftavily-hikari%2Ftavily-hikari-cli%2F@53f53bd704d6dd2e5691c376a795cdf507b2e4618151bad619bf6b313cf95839
Security Audit — socket — tavily-hikari-cli