github not yet analyzed

Tavily

github

Search the web with fast, accurate results optimized for AI. Get clean, structured answers with source URLs and relevance scoring.

maintainer
Tavily
license
first seen
2026-05-22
last seen
2026-06-17
releases · 30d
0
short id
risk insufficient evidence

Insufficient evidence to grade. This server's source has not been statically analyzed, so a low grade would only mean "nothing found", not "nothing there". We don't show a reassuring grade we can't stand behind. Attested signals (CVEs, provenance) below still apply.

Once the source is analyzed (see the analysis flag in the header), a graded score appears here. How analysis works: methodology.

graded 8m ago · see ecosystem CVEs →

risk trajectory 2 movements
  • A · 6B · 27
  • A · 12A · 6
capability exposure grade factor +14
Inferred surface — each links to servers holding it:
vulnerabilities 0 CVEs

No known CVEs for this server.

tool safety 3 findings · grade factor +16
  1. hightoxic flow (lethal trifecta)

    lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil

  2. lowexfiltration combotavily_search

    single tool reads + sends: net, db

  3. lowexfiltration combotavily_skill

    single tool reads + sends: net, db

other grade factors evidence elsewhere
embed badge readme-ready
live risk-grade badge preview [![MCP Observatory risk grade](https://mcpobservatory.com/servers/smithery:Tavily/badge.svg)](https://mcpobservatory.com/servers/smithery:Tavily/security)

Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of Tavily.