Skip to content

Add Trustabl security scanning to CI - #2

Open
kathrina-trustabl wants to merge 1 commit into
DeepFlow-research:mainfrom
kathrina-trustabl:add-trustabl-action
Open

Add Trustabl security scanning to CI#2
kathrina-trustabl wants to merge 1 commit into
DeepFlow-research:mainfrom
kathrina-trustabl:add-trustabl-action

Conversation

@kathrina-trustabl

Copy link
Copy Markdown

We came across your repo and we like that you're developing a research platform for autonomous agents that orchestrate complex workflows with human and AI collaborators. We scanned the repo, and noticed agent runtime reliability findings that might be worth reviewing.

  1. [MEDIUM] Project uses default OpenAI tracing
    What it means: The project uses the OpenAI Agents SDK with default tracing enabled.

  2. [MEDIUM] Mutating tool has no idempotency key
    File: manager_agent_gym/core/workflow_agents/tools/communication.py
    What it means: Tool name suggests a side effect (create/send/refund/…).

  3. [MEDIUM] Mutating tool has no idempotency key
    File: manager_agent_gym/core/workflow_agents/tools/communication_di.py
    What it means: Tool name suggests a side effect (create/send/refund/…).

Recommendations are based on our understanding of agent runtime reliability, some findings may be intentional. Please let us know if this was intentional or if our findings are helpful so we can improve the accuracy of the scanner.

Best,
Trustabl.ai
Open-source AI agent reliability scanner (runs locally, GitHub Action)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant