
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
taufunctions
Advanced tools
TauFunctions CLI - serverless function management for coding agents. Deploy, invoke, monitor. As easy as git.
Serverless functions for coding agents — deploy, invoke, and monitor from one CLI. As easy as git.
git for your code. tau for your functions.
Your agent writes a webhook handler, a cron job, a data transform — then hits a wall: AWS consoles, IAM policies, YAML, a deploy pipeline it can't drive. So you become the middleman, clicking through Lambda screens for code you didn't write. TauFunctions is the serverless platform your agent runs itself: one install, and it creates, deploys, invokes, and monitors its own functions — from the terminal, with plain JSON in and out.
Works with: Claude Code · Cursor · Cline · Windsurf · Aider · Codex · any MCP client
Create to invoked function in 60 seconds — watch the full demo.
npm install -g taufunctions
The npm package is taufunctions; the command is tau.
# Sign up
tau signup you@example.com --tenant my-project
# Create a function from a file
tau fn create "process-order" -r nodejs20 --file handler.js
# Deploy it
tau deploy <function-id>
# Invoke with a JSON payload
tau invoke <function-id> '{"orderId": "ORD-001"}'
# Watch it run
tau logs <function-id>
tau stats <function-id>
# Full reference
tau --help
A function on TauFunctions is exactly what your agent already has in its context: a handler file and a runtime. No zip bundles, no execution roles, no API Gateway wiring, no infrastructure-as-code detour just to run 20 lines of JavaScript.
# The whole deploy story:
tau fn create "resize-image" -r nodejs20 --file resize.js
tau deploy $FN
tau invoke $FN '{"url": "https://example.com/photo.jpg", "width": 800}'
Create → deploy → invoke is three commands, and every one returns structured output your agent can parse with --json.
Shipping v2 doesn't mean a new pipeline run. Push new code at an existing function and redeploy — the function ID, URL, and history stay put.
tau fn code $FN --file hello.js # swap in the new handler
tau deploy $FN # redeploy
tau invoke $FN '{"version": 2}' # verify
No CloudWatch spelunking. Invocation counts, durations, error rates, and execution logs are one command each — formatted for humans, --json for agents.
tau stats $FN # invocations, avg duration, error rate
tau logs $FN --tail 20 # recent executions
tau limits # your plan's quotas and current usage
tau runtimes
Node.js 18/20/22, Python 3.11/3.12, Go 1.21/1.22, Ruby 3.2, and Rust 1.75. Node.js functions execute today on auto-scaling Docker Swarm containers; the remaining runtimes are rolling out on the same executor.
Prefer tools over a CLI? tau ships an MCP server. Point Claude Code (or any MCP client) at it and your agent gets 12 native tools: create, deploy, invoke, update, delete, logs, stats, runtimes, limits, health — the whole function lifecycle.
claude mcp add taufunctions -- tau mcp-serve
For clients that use a JSON config (Cline, Cursor, Windsurf), pass your API key via the TAU_API_KEY environment variable. The MCP server runs outside your project directory, so it will not pick up .tau/config.json:
{
"mcpServers": {
"taufunctions": {
"command": "tau",
"args": ["mcp-serve"],
"env": { "TAU_API_KEY": "tf_your_key_here" }
}
}
}
No CLI at all? Claude Web, Claude Desktop, Raycast, or any hosted MCP client can connect straight to our remote server. Same 12 tools, same API key, nothing to install:
URL: https://mcp.taufunctions.com/sse
Auth: Authorization: Bearer YOUR_API_KEY
No key yet? Connect without one — the server boots in onboarding mode with a tau_signup tool that provisions your account and hands your agent a live key in the same session.
tau mcp-serve) or fully remote (mcp.taufunctions.com): Claude Code, Claude Web, Cursor, Raycast, any MCP client--json for structured, parseable resultsPricing: per-invocation billing, no idle cost. Details.
tau login --key YOUR_KEY # saves to .tau/config.json (project-local)
tau login --key YOUR_KEY --global # saves to ~/.tau/config.json (global)
tau config # show which config is active
Local config overrides global. Add .tau/ to your .gitignore.
Add to your CLAUDE.md, .cursorrules, .clinerules, .windsurfrules, or AGENTS.md:
## TauFunctions
Use the tau CLI for serverless function management.
Key is in .tau/config.json (auto-loaded).
If not configured: tau login --key YOUR_KEY
Run tau --help for the full command reference.
Every time my agent needed "just a small endpoint," the answer was a detour through cloud consoles it couldn't drive — so I ended up clicking through deploy screens for code I didn't write. TauFunctions is the serverless platform the agent runs itself. It's early and I'm iterating fast: if something's rough or missing, tell me — I read everything.
Proprietary - Tyga.Cloud Ltd. See LICENSE.
FAQs
TauFunctions CLI - serverless function management for coding agents. Deploy, invoke, monitor. As easy as git.
The npm package taufunctions receives a total of 0 weekly downloads. As such, taufunctions popularity was classified as not popular.
We found that taufunctions demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.