tavily-hikari-extract
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but its actual footprint relies on an unverified CLI and routes both requests and tokens through a third-party Hikari proxy instead of Tavily's official direct tooling. The install/provenance gap plus credentialed intermediary data flow makes the skill high risk for a simple URL extraction task.
Confidence: 91%Severity: 84%
Audit Metadata