tavily-hikari-cli
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for a managed Hikari deployment, but it routes Tavily activity and credentials through a non-official intermediary and requires an unverifiable wrapper CLI. That makes the main risk credential forwarding and full request visibility by third-party code/service, not confirmed malware.
Confidence: 86%Severity: 84%
Audit Metadata