Add Trustabl security scanning to CI - #1
Open
joshua-trustabl wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I came across your repo and I like the way you demonstrate practical LLM agent patterns using modern SDKs like OpenAI Agents and CrewAI, making it easy for developers to get started with agentic workflows. I scanned the repo, and noticed some agent runtime reliability findings that might be worth reviewing.
Add input_guardrails for WebSearchTool usage
In Agentic AI/02-OpenAI Agents SDK/code/search_agent.py, the agent uses WebSearchTool without input_guardrails configured. This could allow malicious or unexpected user input to trigger unsafe web searches or expose the agent to harmful content during tool execution.
Configure agent safety_settings for code execution
In Agentic AI/03-CrewAI/code/coder/src/coder/crew.py, the agent enables built-in code execution via allow_code_execution=True without explicit safety_settings. This increases the risk of unintended or unsafe code interpretation during agent execution if no additional safeguards are in place.
Configure agent safety_settings for code execution
In Agentic AI/03-CrewAI/code/engineering_team/src/engineering_team/crew.py, the agent enables built-in code execution via allow_code_execution=True without explicit safety_settings. This increases the risk of unintended or unsafe code interpretation during agent execution if no additional safeguards are in place.
Recommendations are based on our understanding of agent runtime reliability, some findings may be intentional. Please let us know if this was intentional or if our findings are helpful so we can improve the accuracy of the scanner.
Best,
Trustabl.ai
Open-source AI agent reliability scanner (runs locally, GitHub Action)