Tavily MCP Server ↗
Tavily MCP Server is an officially published MCP server from Tavily. Anomity scores its risk at 10 out of 100 (low).
Analysis summary
Tavily MCP Server is an officially published MCP server from Tavily. Anomity scores its risk at 10 out of 100 (low).
Tavily's official server provides search and data extraction designed for LLM pipelines, returning summarised, source-attributed results intended to be dropped straight into a context window.
Outbound network access is its only capability. Its source attribution is a genuine security feature, not just a citation nicety: an agent that reports where a claim came from lets a human check whether the claim came from somewhere trustworthy, which is the only practical defence against retrieval-borne injection at the moment. Prefer retrieval tools that preserve provenance over ones that return anonymous text.
Why this entry scored 10 out of 100
This profile starts at the catalog's neutral base of 50. Because the entry is officially published, trust adjusts the score by -40. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 10, placing it in the low band.
Findings
-
Published by the vendor Trust offset
Capabilities
Every capability the entry declares, with the security implication of each.
-
network:outboundOutbound networkCan make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access.