Skip to content

Add Trustabl Agent Scanner to CI - #198

Open
trustabl-kathrina wants to merge 1 commit into
sunblaze-ucb:mainfrom
trustabl-kathrina:add-trustabl-action
Open

trustabl-kathrina wants to merge 1 commit into
sunblaze-ucb:mainfrom
trustabl-kathrina:add-trustabl-action

Conversation

@trustabl-kathrina

Copy link
Copy Markdown

We came across your repo and we like how you provide a framework for evaluating the security of AI systems through plug-in components, allowing for diverse attack scenarios and target types. We scanned the repo, and noticed agent runtime reliability findings that might be worth reviewing.

  1. [LOW] In AGENTS.md/CLAUDE.md, the project uses CrewAI in code but ships no agent-guidance doc (AGENTS.md/CLAUDE.md). This means:
    The project lacks documentation outlining how to safely and effectively guide the behavior of the CrewAI agent, potentially leading to unintended or harmful outcomes during runtime.

  2. [LOW] In AGENTS.md/CLAUDE.md, a repository that builds on the Claude Agent SDK but ships no agent-guidance doc — CLAUDE.md. This means:
    Without specific guidance on configuring and interacting with the Claude Agent SDK, developers may inadvertently introduce vulnerabilities or unexpected behavior into their applications.

  3. [LOW] In AGENTS.md/CLAUDE.md, he project uses LangChain / LangGraph in code but ships no agent-guidance doc (AGENTS.md/CLAUDE.md). This means:
    The absence of documentation on safely guiding LangChain and LangGraph agents can result in unpredictable behavior and potential security risks during runtime interactions with the AI system.

Recommendations are based on our understanding of agent runtime reliability, some findings may be intentional. Please let us know if this was intentional or if our findings are helpful so we can improve the accuracy of the scanner.

Best,
Trustabl.ai
Open-source AI agent reliability scanner (runs locally, GitHub Action)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant