
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@scavio/ai-sdk
Advanced tools
Scavio search tools for the Vercel AI SDK (Google, YouTube, Reddit, Amazon, Walmart, TikTok, Instagram).
Scavio search tools for the Vercel AI SDK. Give any AI SDK agent real-time search across Google, YouTube, Reddit, Amazon, Walmart, TikTok, and Instagram via the Scavio API.
npm install @scavio/ai-sdk ai
export SCAVIO_API_KEY=sk_live_your_key
ai and zod are peer dependencies; scavio (the JS SDK) is bundled.
import { generateText, stepCountIs } from "ai";
import { openai } from "@ai-sdk/openai";
import { scavioSearch, scavioTools } from "@scavio/ai-sdk";
// A single tool:
const res = await generateText({
model: openai("gpt-4o-mini"),
tools: { scavio_search: scavioSearch({ maxResults: 5 }) },
stopWhen: stepCountIs(3),
prompt: "Find the official GitHub repo of the Agno framework",
});
// Or all tools at once:
const res2 = await generateText({
model: openai("gpt-4o-mini"),
tools: scavioTools(),
stopWhen: stepCountIs(3),
prompt: "Compare prices for a mechanical keyboard on Amazon and Walmart",
});
| Factory | Tool name | Provider |
|---|---|---|
scavioSearch | scavio_search | Google web search |
scavioYoutubeSearch | scavio_youtube_search | YouTube video search |
scavioRedditSearch | scavio_reddit_search | Reddit (2 credits) |
scavioAmazonSearch | scavio_amazon_search | Amazon products |
scavioWalmartSearch | scavio_walmart_search | Walmart products |
scavioTiktokSearch | scavio_tiktok_search | TikTok videos |
scavioInstagramSearch | scavio_instagram_search | Instagram users |
scavioTools | all of the above | bundle for tools: |
Each factory accepts { apiKey?, maxResults?, ...ScavioConfig }. The key falls back to SCAVIO_API_KEY.
Get a key at dashboard.scavio.dev.
MIT
FAQs
Scavio search and URL-extraction tools for the Vercel AI SDK (extract any URL, plus Google, YouTube, Reddit, Amazon, Walmart, TikTok, Instagram).
The npm package @scavio/ai-sdk receives a total of 0 weekly downloads. As such, @scavio/ai-sdk popularity was classified as not popular.
We found that @scavio/ai-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.