tavily-hikari-map
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the skill replaces the official Tavily CLI/API with a third-party Hikari wrapper, requires a non-official token, and routes requests through an intermediary facade. That combination creates meaningful supply-chain and credential/data-flow risk disproportionate to a simple site-mapping skill.
Confidence: 89%Severity: 78%
Audit Metadata