add-tavily-tool

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses system commands such as docker inspect to discover the local dashboard environment and ncl to manage agent group configurations. It also employs perl for automated cleanup of instructions in the removal phase.\n- [EXTERNAL_DOWNLOADS]: The skill adds a versioned dependency on the mcp-remote CLI tool to the project manifest.\n- [REMOTE_CODE_EXECUTION]: The skill establishes a bridge to the remote Tavily MCP server, enabling web search and extraction capabilities through a standard protocol.\n- [PROMPT_INJECTION]: The skill implements persistent instruction blocks for error handling and credential redirection. These instructions include explicit security guidance for the agent to avoid direct handling of user secrets, which aligns with safety best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:11 AM
Security Audit — agent-trust-hub — add-tavily-tool