Skip to content

Add Trustabl Agent Scanner to CI - #191

Open
joshua-trustabl wants to merge 1 commit into
future-agi:mainfrom
joshua-trustabl:add-trustabl-action
Open

Add Trustabl Agent Scanner to CI#191
joshua-trustabl wants to merge 1 commit into
future-agi:mainfrom
joshua-trustabl:add-trustabl-action

Conversation

@joshua-trustabl

Copy link
Copy Markdown

We came across your repo and we like that it provides a framework for tracing AI applications, allowing users to monitor and understand the flow of data and execution within complex AI systems. We scanned the repo, and noticed agent runtime reliability findings that might be worth reviewing.

  1. [HIGH] Tool body calls eval/exec/compile on dynamic input
    File: python/frameworks/agno/examples/agent_with_tools.py
    What it means: The tool body invokes Python's eval, exec, or compile.

  2. [HIGH] LangChain tool fetches a caller-controlled URL (SSRF)
    File: python/frameworks/langchain/examples/exchange_rate_tool.py
    What it means: This LangChain tool issues an HTTP request whose URL is built from a parameter or interpolated value rather than a fixed literal.

  3. [HIGH] LangChain tool fetches a caller-controlled URL (SSRF)
    File: python/frameworks/langchain/examples/tool_calling_agent.py
    What it means: This LangChain tool issues an HTTP request whose URL is built from a parameter or interpolated value rather than a fixed literal.

Recommendations are based on our understanding of agent runtime reliability, some findings may be intentional. Please let us know if this was intentional or if our findings are helpful so we can improve the accuracy of the scanner.

Best,
Trustabl.ai
Open-source AI agent reliability scanner (runs locally, GitHub Action)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant