Skip to content

Add Trustabl Agent Scanner to CI - #172

Open
kathrina-trustabl wants to merge 1 commit into
TSchonleber:mainfrom
kathrina-trustabl:add-trustabl-action
Open

Add Trustabl Agent Scanner to CI#172
kathrina-trustabl wants to merge 1 commit into
TSchonleber:mainfrom
kathrina-trustabl:add-trustabl-action

Conversation

@kathrina-trustabl

Copy link
Copy Markdown

We came across your repo and we like how you are enabling agents to remember past interactions and decisions, creating a persistent memory system.

  1. [MEDIUM] Skill fetches untrusted external content
    File: SKILL.md
    What it means: This skill's body references an external http(s) URL. It could be vulnerable to malicious injection attacks if the URL points to a compromised site.

  2. [LOW] Missing descriptions for potential vulnerabilities
    File: SECURITY-POLICY.md
    What it means: The security policy document lacks specific descriptions for common vulnerabilities like cross-site scripting (XSS), SQL injection, or buffer overflows. This makes it difficult for developers to understand and mitigate these risks.

Recommendations are based on our understanding of agent runtime reliability, some findings may be intentional. Please let us know if this was intentional or if our findings are helpful so we can improve the accuracy of the scanner.

Best,
Trustabl.ai
Open-source AI agent reliability scanner (runs locally, GitHub Action)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant