tavily-hikari-extract

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual footprint relies on an unverified CLI and routes both requests and tokens through a third-party Hikari proxy instead of Tavily's official direct tooling. The install/provenance gap plus credentialed intermediary data flow makes the skill high risk for a simple URL extraction task.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Jul 15, 2026, 04:21 PM
Package URL
pkg:socket/skills-sh/IvanLi-CN%2Ftavily-hikari%2Ftavily-hikari-extract%2F@ee70da6a0087912f8ea8c95897713a6f7c51423851116330b4aa059220120072
Security Audit — socket — tavily-hikari-extract