Back to plugin

Security audit

Tavily OpenClaw plugin

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tavily web search and extraction plugin that uses a Tavily API key to send user-directed search queries and URLs to Tavily.

Install only if you are comfortable sending search queries, supplied URLs, and extraction targets to Tavily or a configured Tavily-compatible base URL. Avoid submitting secrets, private internal URLs, or confidential research targets unless your organization approves that use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents search and URL extraction features but does not clearly disclose that user queries, supplied URLs, and potentially extracted page content are transmitted to an external Tavily service. This creates a privacy and data-handling risk because users or downstream agents may provide sensitive prompts, internal URLs, or confidential research targets without realizing they are leaving the local trust boundary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.