tavily

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends installing the tvly CLI by downloading a shell script from the vendor's official domain (https://cli.tavily.com/install.sh) and piping it directly to bash. This represents the author's official distribution channel for the utility tool.
  • [COMMAND_EXECUTION]: The skill uses the tvly command-line tool for all operations, including search, extract, map, crawl, and research subcommands.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from the internet, which is its primary purpose but inherently presents a surface for indirect prompt injection.
  • Ingestion points: Content retrieved from external websites via tvly is stored in the .tavily/ directory and subsequently read into the agent's context.
  • Boundary markers: The instructions do not define specific boundary markers or delimiters for the agent to use when reading content from the retrieved files.
  • Capability inventory: The skill has access to network operations (via the CLI), shell command execution, and file system read/write capabilities.
  • Sanitization: There are no explicit instructions for the agent to sanitize, filter, or validate the content retrieved from external URLs before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 06:13 AM
Security Audit — agent-trust-hub — tavily