tavily-research
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructs the user to install the
tavily-clipackage viauvorpip. This is the official CLI for the Tavily research service and is considered a standard dependency for this skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes multi-source research data from external websites. 1. Ingestion points: Untrusted data enters the agent context via the
tvly researchcommand results in SKILL.md. 2. Boundary markers: The skill includes a Verification Protocol in SKILL.md requiring the agent to spot-check citations and handle contradictory sources. 3. Capability inventory: The skill has the capability to execute shell commands (tvly) and write output to files (-o). 4. Sanitization: The skill relies on manual citation verification steps and material claim spot-checking rather than automated sanitization or escaping.
Audit Metadata