tavily

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-hosted Tavily integration, but it introduces a third-party intermediary for Tavily auth and data instead of using Tavily's native API path. The install source is official npm and not obviously malicious, yet the unpinned `@latest` CLI execution and credential/data brokerage through Membrane create medium security risk disproportionate to a simple Tavily integration.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
May 4, 2026, 11:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftavily%2F@5a8c933b6f734ca790a45d6f00bee619ba569c62
Security Audit — socket — tavily