tavily-search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web sources which could potentially contain malicious instructions.
- Ingestion points: Search results, content snippets, and raw page content retrieved via the
tvly searchcommand as described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded in search results.
- Capability inventory: The skill's capabilities are restricted to the
tvlycommand line tool within the Bash environment. - Sanitization: No specific content sanitization or validation steps are defined for the retrieved data before it enters the agent context.
- [COMMAND_EXECUTION]: The skill uses the
tvlyCLI to perform its primary function. - The execution is scope-limited via the
allowed-toolsmetadata, which restricts the Bash tool to onlytvlycommands, adhering to the principle of least privilege. - The skill includes clear instructions for handling authentication (
tvly login) and environment-specific behaviors, such as avoiding interactive flows in unattended environments.
Audit Metadata