tavily-key-generator-proxy
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its actual purpose is account farming and proxying pooled Tavily keys to bypass normal service limits, which is disproportionate to a typical API integration. The main risk comes from executing an unrelated third-party GitHub project, forwarding secrets to external CAPTCHA/email services, and routing all API traffic through a custom gateway that impersonates real Tavily key usage.
Confidence: 90%Severity: 90%
Audit Metadata