Skip to content
This repository was archived by the owner on Aug 13, 2026. It is now read-only.

Add Scavio tool node (188 tools across 32 platforms) - #6595

Open
scavio-ai wants to merge 9 commits into
FlowiseAI:mainfrom
scavio-ai:feat/scavio-tool-node
Open

scavio-ai wants to merge 9 commits into
FlowiseAI:mainfrom
scavio-ai:feat/scavio-tool-node

Conversation

@scavio-ai

@scavio-ai scavio-ai commented Jul 3, 2026 •

Copy link
Copy Markdown

Description

Adds a Scavio tool node under Tools, alongside the existing search nodes (Tavily, SerpAPI, Brave, Exa). Scavio is a real-time search API for AI agents: one key over Google, YouTube, Amazon, Walmart, eBay, Target, Home Depot, Zillow, Redfin, Booking.com, Airbnb, TripAdvisor, Yelp, Indeed, Glassdoor, the Apple App Store, Google Play, SEC EDGAR, Companies House, G2, Capterra, Google Ads Transparency, the Meta Ad Library, Reddit, TikTok, TikTok Shop, Instagram, Threads, X, LinkedIn and Kuaishou, plus a generic "read any URL as HTML/Markdown/text" endpoint. Everything comes back as clean JSON.

Heads-up for reviewers: this branch changed shape since it was opened.
The original version of this PR was a single scavio_search tool (3 files, 229 lines) wrapping one Google endpoint. It has been rebased onto current main and rewritten as a table-driven multi-tool node covering the whole API — 188 tools across 32 platforms. If you reviewed the earlier diff, please re-read rather than re-skim; the two commits below are ordered so the architecture change and the endpoint coverage can be read separately.

Files

  • packages/components/nodes/tools/Scavio/core.ts — the endpoint table and the tool implementation
  • packages/components/nodes/tools/Scavio/Scavio.ts — the node
  • packages/components/nodes/tools/Scavio/scavio.svg — icon
  • packages/components/credentials/ScavioApi.credential.ts — API-key credential

Node registration is automatic (Flowise scans the folders); nothing else in the repo is touched.

Shape of the node

The same multi-tool pattern Flowise already uses for Gmail / Google Drive / Stripe: pick a Platform, tick the Actions you want, and init() returns one DynamicStructuredTool per ticked action. A user who only wants Google search ticks one action and gets one tool, exactly like the first version of this PR — the surface is opt-in, not 188 tools shoved into an agent at once.

core.ts holds one row per endpoint: path, credit cost, agent-facing description and a zod schema. The node's multiOptions lists are generated from that table by toNodeOptions(), so the UI cannot drift from the API and adding an endpoint is a one-row change.

Every tool POSTs to https://api.scavio.dev through secureAxiosRequest with Authorization: Bearer <key> and returns the response body verbatim. Verbatim matters: Google responses are flat (organic_results[]) while every other family wraps its payload in data, so unwrapping in the node would silently break half the tools.

Commits

  1. scavio node: table-driven endpoint registry, one tool per endpoint — the architecture change (1 tool -> 97 across 10 platforms).
  2. scavio node: 22 more platforms + URL extraction — eBay, Target, Home Depot, Zillow, Redfin, Booking, Airbnb, TripAdvisor, Yelp, Indeed, Glassdoor, App Store, Google Play, SEC EDGAR, Companies House, G2, Capterra, Google Ads Transparency, Meta Ad Library, Threads, Kuaishou and extract; Walmart grows from 2 endpoints to 7. 188 tools, 32 platforms.

Credit costs

Each tool's description ends with what one call costs, so an agent can reason about spend. Most endpoints are a flat 1 or 2 credits. Three surfaces are priced from the request body rather than the path, and those say so instead of quoting a flat number:

  • Walmart search/category — 1 credit on domain com/ca, 2 on com.mx
  • Threads profile/user posts/user replies — 2 credits by user_id, 4 by username
  • extract — 1 credit in normal/advanced mode, 2 in ultra

Testing

  • pnpm build in packages/components passes (tsc type-checks the whole table).
  • eslint and prettier clean.
  • The table was driven against the live API through the node's own _call() path: eBay search, Zillow search, App Store search, SEC lookup, Meta Ad Library search, extract, Walmart search and Companies House search all returned 200 at the documented credit cost.
  • Manual UI check: add a Tools > Scavio node, create a Scavio API credential with a real key, pick a platform, tick a couple of actions, wire it to an agent.

How it works

  • User creates a Scavio API credential (free key with 50 credits at https://dashboard.scavio.dev/sign-up).
  • The node returns one tool per ticked action; each tool calls the matching Scavio endpoint and returns JSON.

Docs: https://scavio.dev/docs

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new Scavio search tool and its corresponding credential configuration to enable real-time web searches. The feedback highlights a security concern regarding Server-Side Request Forgery (SSRF) due to the direct use of raw axios instead of the project's centralized secureAxiosRequest wrapper. Additionally, it is recommended to validate the presence of the Scavio API key during initialization to prevent silent runtime failures.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@@ -0,0 +1,188 @@
import axios from 'axios'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-high high

To prevent Server-Side Request Forgery (SSRF) vulnerabilities, Flowise uses a centralized HTTP security wrapper (httpSecurity.ts) that implements deny-list validation and IP pinning logic. Directly importing and invoking raw axios bypasses these SSRF mitigations entirely. Please use secureAxiosRequest from ../../../src/httpSecurity instead of raw axios.

Suggested change
import axios from 'axios'
import { secureAxiosRequest } from '../../../src/httpSecurity'

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 6378e8a — the raw axios import was replaced with secureAxiosRequest from ../../../src/httpSecurity.

The HTTP layer has since moved out of Scavio.ts into core.ts (8366ff8, table-driven endpoint registry), which is why this thread now points at a line that no longer exists. On the current head 8be074c the import is at packages/components/nodes/tools/Scavio/core.ts:4. There are no remaining axios references anywhere in this node.

Comment on lines +50 to +55
const { data } = await axios.post('https://api.scavio.dev/api/v2/google', body, {
headers: {
'Content-Type': 'application/json',
Authorization: `Bearer ${this.apiKey}`
}
})

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-high high

Use the secured secureAxiosRequest wrapper instead of raw axios to ensure that all outbound requests are properly validated against the SSRF deny-list.

            const { data } = await secureAxiosRequest({
                url: 'https://api.scavio.dev/api/v2/google',
                method: 'POST',
                data: body,
                headers: {
                    'Content-Type': 'application/json',
                    Authorization: 'Bearer ' + this.apiKey
                }
            })

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 6378e8a — this call now goes through secureAxiosRequest.

The request layer moved from Scavio.ts into core.ts in 8366ff8, so on the current head 8be074c it is at packages/components/nodes/tools/Scavio/core.ts:3719. That is the single outbound call site for the node — all 188 endpoints route through it, so nothing bypasses the SSRF deny-list.

Comment on lines +167 to +168
const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

It is recommended to validate that the scavioApiKey is present during the node's initialization. Throwing a clear error when the API key is missing prevents silent failures or confusing runtime errors when the tool is executed.

Suggested change
const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData)
const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData)
if (!scavioApiKey) {
throw new Error('Scavio API Key is missing. Please connect your Scavio API credential.')
}
References
  1. When a feature requires a specific configuration (e.g., an API key for a sandboxed environment), it is preferable to throw an error if the configuration is missing rather than silently falling back to a different implementation.

@scavio-ai

Copy link
Copy Markdown
Author

Thanks for the review. Addressed both points: the node now uses secureAxiosRequest from httpSecurity instead of raw axios, and init() throws a clear error when the API key is missing.

@scavio-ai

Copy link
Copy Markdown
Author

Hi maintainers — the earlier automated review feedback is addressed (secure HTTP wrapper + API key validation) and the branch is conflict-free and updated to the current v2 search endpoint. Could someone approve the CI run and take a look when you have a moment?

core.ts holds path, credit cost, description and a zod schema per endpoint;
the node's Platform + Actions multiOptions are generated from it, so the UI
cannot drift from the API. 97 tools across 10 platforms, replacing the single
google-search tool.
…rms)

Adds eBay, Target, Home Depot, Zillow, Redfin, Booking, Airbnb, TripAdvisor,
Yelp, Indeed, Glassdoor, App Store, Google Play, SEC EDGAR, Companies House,
G2, Capterra, Google Ads Transparency, Meta Ad Library, Threads, Kuaishou and
the extract endpoint; Walmart grows from 2 endpoints to 7.

Endpoints whose credit cost is a function of the request body (walmart by
domain, threads by user_id vs username, extract by mode) carry a creditNote
and never advertise a flat cost.
@scavio-ai
scavio-ai force-pushed the feat/scavio-tool-node branch from 860ef7a to d1992f1 Compare August 11, 2026 00:38
@scavio-ai scavio-ai changed the title Add Scavio tool node Add Scavio tool node (188 tools across 32 platforms) Aug 11, 2026
@scavio-ai

Copy link
Copy Markdown
Author

Heads-up: I've rebased this onto current main and pushed a substantial rewrite, so the diff is not what it was when the PR was opened.

What changed: the node was one scavio_search tool over a single Google endpoint (229 lines). It is now a table-driven multi-tool node — pick a Platform, tick Actions, get one DynamicStructuredTool per ticked action — covering 188 endpoints across 32 platforms, same pattern as the existing Gmail / Google Drive / Stripe nodes. Ticking one action still yields exactly one tool, so the surface stays opt-in.

The two points from the earlier automated review still hold in the new code: all HTTP goes through secureAxiosRequest, and init() throws when the credential has no key.

Split into two commits so it can be read in stages: the architecture change first, then the added platforms. pnpm build in packages/components passes, eslint/prettier are clean, and the table was exercised against the live API through the node's own _call() path.

Happy to split this into two PRs (registry first, platforms second) if that reviews better.

This branch has not been deployed

No deployments
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants