Cracken + Tavily
Cracken calls Tavily mid-operation to search and extract the live web. It gets back clean text on a CVE or product, instead of HTML it would have to scrape.
Connecting Tavily
- Connect with
A Tavily API key from app.tavily.com
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle; a Tavily account (free tier available)
What Cracken gets from Tavily
An LLM-ready answer string for the query
A ranked results list, each result with title, url and a content snippet
An executed_at timestamp and the provider label on each search entry
What Tavily does not do
Returns search text only — no images and no raw page HTML are fetched; it requires a Tavily API key and is freemium.
How Cracken uses Tavily
- 01
Install Tavily on a Tentacle
- 02
Supply your Tavily API key
- 03
Search while the operation runs
- 04
Confirm the Tentacle is ready
Frequently asked questions
What leaves my environment when Cracken uses Tavily?
Only the search terms and URLs Cracken sends Tavily leave the Tentacle; operation output, captured credentials, and evidence do not.
Do I need a paid Tavily plan?
No — Tavily has a free tier, and the tool works with whatever plan your installed API key belongs to.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
Attack with real Tavily context.
See how Cracken runs Tavily on a Tentacle you host, and proves what it finds end to end.




