tavily-hikari-map

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the skill replaces the official Tavily CLI/API with a third-party Hikari wrapper, requires a non-official token, and routes requests through an intermediary facade. That combination creates meaningful supply-chain and credential/data-flow risk disproportionate to a simple site-mapping skill.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Jul 15, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/IvanLi-CN%2Ftavily-hikari%2Ftavily-hikari-map%2F@51fc247fb7a4e06ae129dea14de129b39f60889aadda46a37e7c37a49661bb84
Security Audit — socket — tavily-hikari-map