tavily
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends installing the
tvlyCLI by downloading a shell script from the vendor's official domain (https://cli.tavily.com/install.sh) and piping it directly tobash. This represents the author's official distribution channel for the utility tool. - [COMMAND_EXECUTION]: The skill uses the
tvlycommand-line tool for all operations, includingsearch,extract,map,crawl, andresearchsubcommands. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from the internet, which is its primary purpose but inherently presents a surface for indirect prompt injection.
- Ingestion points: Content retrieved from external websites via
tvlyis stored in the.tavily/directory and subsequently read into the agent's context. - Boundary markers: The instructions do not define specific boundary markers or delimiters for the agent to use when reading content from the retrieved files.
- Capability inventory: The skill has access to network operations (via the CLI), shell command execution, and file system read/write capabilities.
- Sanitization: There are no explicit instructions for the agent to sanitize, filter, or validate the content retrieved from external URLs before processing it.
Audit Metadata