tavily-extract

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts content from external URLs provided by the user or discovered during search, which introduces a surface for indirect prompt injection if the retrieved content contains adversarial instructions.
  • Ingestion points: Web content is retrieved and converted to markdown or text via the tvly extract command as described in SKILL.md.
  • Boundary markers: The documentation encourages using the --json flag to return structured data, which helps the agent distinguish between tool output and extracted page content, although it does not mandate specific LLM-side boundary markers.
  • Capability inventory: The skill is restricted to the tvly CLI tool within the Bash environment (frontmatter configuration).
  • Sanitization: The instructions do not specify any explicit sanitization or filtering of the extracted web content before it is returned to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:07 PM
Security Audit — agent-trust-hub — tavily-extract