tavily-extract
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts content from external URLs provided by the user or discovered during search, which introduces a surface for indirect prompt injection if the retrieved content contains adversarial instructions.
- Ingestion points: Web content is retrieved and converted to markdown or text via the
tvly extractcommand as described in SKILL.md. - Boundary markers: The documentation encourages using the
--jsonflag to return structured data, which helps the agent distinguish between tool output and extracted page content, although it does not mandate specific LLM-side boundary markers. - Capability inventory: The skill is restricted to the
tvlyCLI tool within the Bash environment (frontmatter configuration). - Sanitization: The instructions do not specify any explicit sanitization or filtering of the extracted web content before it is returned to the agent's context.
Audit Metadata