Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces a new Scavio search tool and its corresponding credential configuration to enable real-time web searches. The feedback highlights a security concern regarding Server-Side Request Forgery (SSRF) due to the direct use of raw axios instead of the project's centralized secureAxiosRequest wrapper. Additionally, it is recommended to validate the presence of the Scavio API key during initialization to prevent silent runtime failures.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| @@ -0,0 +1,188 @@ | |||
| import axios from 'axios' | |||
There was a problem hiding this comment.
To prevent Server-Side Request Forgery (SSRF) vulnerabilities, Flowise uses a centralized HTTP security wrapper (httpSecurity.ts) that implements deny-list validation and IP pinning logic. Directly importing and invoking raw axios bypasses these SSRF mitigations entirely. Please use secureAxiosRequest from ../../../src/httpSecurity instead of raw axios.
| import axios from 'axios' | |
| import { secureAxiosRequest } from '../../../src/httpSecurity' |
There was a problem hiding this comment.
Fixed in 6378e8a — the raw axios import was replaced with secureAxiosRequest from ../../../src/httpSecurity.
The HTTP layer has since moved out of Scavio.ts into core.ts (8366ff8, table-driven endpoint registry), which is why this thread now points at a line that no longer exists. On the current head 8be074c the import is at packages/components/nodes/tools/Scavio/core.ts:4. There are no remaining axios references anywhere in this node.
| const { data } = await axios.post('https://api.scavio.dev/api/v2/google', body, { | ||
| headers: { | ||
| 'Content-Type': 'application/json', | ||
| Authorization: `Bearer ${this.apiKey}` | ||
| } | ||
| }) |
There was a problem hiding this comment.
Use the secured secureAxiosRequest wrapper instead of raw axios to ensure that all outbound requests are properly validated against the SSRF deny-list.
const { data } = await secureAxiosRequest({
url: 'https://api.scavio.dev/api/v2/google',
method: 'POST',
data: body,
headers: {
'Content-Type': 'application/json',
Authorization: 'Bearer ' + this.apiKey
}
})There was a problem hiding this comment.
Fixed in 6378e8a — this call now goes through secureAxiosRequest.
The request layer moved from Scavio.ts into core.ts in 8366ff8, so on the current head 8be074c it is at packages/components/nodes/tools/Scavio/core.ts:3719. That is the single outbound call site for the node — all 188 endpoints route through it, so nothing bypasses the SSRF deny-list.
| const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData) | ||
|
|
There was a problem hiding this comment.
It is recommended to validate that the scavioApiKey is present during the node's initialization. Throwing a clear error when the API key is missing prevents silent failures or confusing runtime errors when the tool is executed.
| const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData) | |
| const scavioApiKey = getCredentialParam('scavioApiKey', credentialData, nodeData) | |
| if (!scavioApiKey) { | |
| throw new Error('Scavio API Key is missing. Please connect your Scavio API credential.') | |
| } |
References
- When a feature requires a specific configuration (e.g., an API key for a sandboxed environment), it is preferable to throw an error if the configuration is missing rather than silently falling back to a different implementation.
|
Thanks for the review. Addressed both points: the node now uses |
|
Hi maintainers — the earlier automated review feedback is addressed (secure HTTP wrapper + API key validation) and the branch is conflict-free and updated to the current v2 search endpoint. Could someone approve the CI run and take a look when you have a moment? |
core.ts holds path, credit cost, description and a zod schema per endpoint; the node's Platform + Actions multiOptions are generated from it, so the UI cannot drift from the API. 97 tools across 10 platforms, replacing the single google-search tool.
…rms) Adds eBay, Target, Home Depot, Zillow, Redfin, Booking, Airbnb, TripAdvisor, Yelp, Indeed, Glassdoor, App Store, Google Play, SEC EDGAR, Companies House, G2, Capterra, Google Ads Transparency, Meta Ad Library, Threads, Kuaishou and the extract endpoint; Walmart grows from 2 endpoints to 7. Endpoints whose credit cost is a function of the request body (walmart by domain, threads by user_id vs username, extract by mode) carry a creditNote and never advertise a flat cost.
860ef7a to
d1992f1
Compare
|
Heads-up: I've rebased this onto current What changed: the node was one The two points from the earlier automated review still hold in the new code: all HTTP goes through Split into two commits so it can be read in stages: the architecture change first, then the added platforms. Happy to split this into two PRs (registry first, platforms second) if that reviews better. |
Description
Adds a Scavio tool node under
Tools, alongside the existing search nodes (Tavily, SerpAPI, Brave, Exa). Scavio is a real-time search API for AI agents: one key over Google, YouTube, Amazon, Walmart, eBay, Target, Home Depot, Zillow, Redfin, Booking.com, Airbnb, TripAdvisor, Yelp, Indeed, Glassdoor, the Apple App Store, Google Play, SEC EDGAR, Companies House, G2, Capterra, Google Ads Transparency, the Meta Ad Library, Reddit, TikTok, TikTok Shop, Instagram, Threads, X, LinkedIn and Kuaishou, plus a generic "read any URL as HTML/Markdown/text" endpoint. Everything comes back as clean JSON.Files
packages/components/nodes/tools/Scavio/core.ts— the endpoint table and the tool implementationpackages/components/nodes/tools/Scavio/Scavio.ts— the nodepackages/components/nodes/tools/Scavio/scavio.svg— iconpackages/components/credentials/ScavioApi.credential.ts— API-key credentialNode registration is automatic (Flowise scans the folders); nothing else in the repo is touched.
Shape of the node
The same multi-tool pattern Flowise already uses for Gmail / Google Drive / Stripe: pick a Platform, tick the Actions you want, and
init()returns oneDynamicStructuredToolper ticked action. A user who only wants Google search ticks one action and gets one tool, exactly like the first version of this PR — the surface is opt-in, not 188 tools shoved into an agent at once.core.tsholds one row per endpoint: path, credit cost, agent-facing description and a zod schema. The node'smultiOptionslists are generated from that table bytoNodeOptions(), so the UI cannot drift from the API and adding an endpoint is a one-row change.Every tool POSTs to
https://api.scavio.devthroughsecureAxiosRequestwithAuthorization: Bearer <key>and returns the response body verbatim. Verbatim matters: Google responses are flat (organic_results[]) while every other family wraps its payload indata, so unwrapping in the node would silently break half the tools.Commits
scavio node: table-driven endpoint registry, one tool per endpoint— the architecture change (1 tool -> 97 across 10 platforms).scavio node: 22 more platforms + URL extraction— eBay, Target, Home Depot, Zillow, Redfin, Booking, Airbnb, TripAdvisor, Yelp, Indeed, Glassdoor, App Store, Google Play, SEC EDGAR, Companies House, G2, Capterra, Google Ads Transparency, Meta Ad Library, Threads, Kuaishou andextract; Walmart grows from 2 endpoints to 7. 188 tools, 32 platforms.Credit costs
Each tool's description ends with what one call costs, so an agent can reason about spend. Most endpoints are a flat 1 or 2 credits. Three surfaces are priced from the request body rather than the path, and those say so instead of quoting a flat number:
domaincom/ca, 2 oncom.mxuser_id, 4 byusernameextract— 1 credit innormal/advancedmode, 2 inultraTesting
pnpm buildinpackages/componentspasses (tsctype-checks the whole table).eslintandprettierclean._call()path: eBay search, Zillow search, App Store search, SEC lookup, Meta Ad Library search,extract, Walmart search and Companies House search all returned 200 at the documented credit cost.How it works
Docs: https://scavio.dev/docs