Repository navigation
docs: credit Lling0000 as current owner and RAG module author - #44
Merged
Merged
Annotations
4 errors, 6 warnings, and 3 notices
|
Run trustabl/trustabl-action@v0
Trustabl gate failed: trustabl gated (medium+ or --strict)
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/llmstxt.py#L252
An OpenAI Agents SDK tool that makes a network request without a timeout can hang indefinitely, blocking the agent's run loop and consuming the conversation's wall-clock budget. The SDK does not enforce timeouts on tool code.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/llmstxt.py#L205
An OpenAI Agents SDK tool that makes a network request without a timeout can hang indefinitely, blocking the agent's run loop and consuming the conversation's wall-clock budget. The SDK does not enforce timeouts on tool code.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/ai_crawler_check.py#L257
An OpenAI Agents SDK tool that makes a network request without a timeout can hang indefinitely, blocking the agent's run loop and consuming the conversation's wall-clock budget. The SDK does not enforce timeouts on tool code.
|
|
Complete job
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Run trustabl/trustabl-action@v0
The project uses the OpenAI Agents SDK with default tracing enabled. By default, inputs, tool calls, tool outputs, and agent responses are sent to OpenAI's hosted tracing backend. For projects handling sensitive data (PII, credentials, internal documents), this is a data egress channel that is easy to miss.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/llmstxt.py#L252
An OpenAI Agents SDK tool builds its outbound HTTP URL from a non-literal value — typically a tool parameter interpolated into an f-string or concatenated onto a base URL. Because tool arguments are produced by the model from conversation context (including prior tool output and user input), an attacker who can shape that context can steer the request to an attacker-controlled host or to an internal address the agent's network egress can reach but the model was never meant to touch. The same channel also leaks request bodies (auth headers, JSON payloads, the model's reasoning) to whichever host the URL resolves to, so the failure mode is both SSRF and data exfiltration in one call.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/llmstxt.py#L205
An OpenAI Agents SDK tool builds its outbound HTTP URL from a non-literal value — typically a tool parameter interpolated into an f-string or concatenated onto a base URL. Because tool arguments are produced by the model from conversation context (including prior tool output and user input), an attacker who can shape that context can steer the request to an attacker-controlled host or to an internal address the agent's network egress can reach but the model was never meant to touch. The same channel also leaks request bodies (auth headers, JSON payloads, the model's reasoning) to whichever host the URL resolves to, so the failure mode is both SSRF and data exfiltration in one call.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/ai_crawler_check.py#L257
An OpenAI Agents SDK tool builds its outbound HTTP URL from a non-literal value — typically a tool parameter interpolated into an f-string or concatenated onto a base URL. Because tool arguments are produced by the model from conversation context (including prior tool output and user input), an attacker who can shape that context can steer the request to an attacker-controlled host or to an internal address the agent's network egress can reach but the model was never meant to touch. The same channel also leaks request bodies (auth headers, JSON payloads, the model's reasoning) to whichever host the URL resolves to, so the failure mode is both SSRF and data exfiltration in one call.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/email_report.py#L119
Tool name suggests a side effect (create/send/refund/…). A mutating tool with no idempotency key cannot tell a new request from a retry of one whose result was lost. Retries are not automatic in the OpenAI Agents SDK, but they still happen — the model re-invokes a tool when a result reads as inconclusive, an orchestrator or your own retry policy re-issues after a timeout, or a response is lost after the side effect already committed (at-least-once delivery). Without a key the same action fires twice; the downstream service must also honor the key for this to help.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/ai_crawler_check.py#L257
When a tool raises an exception, the OpenAI Agents SDK surfaces the exception's string representation to the model by default. The model receives an opaque error with no recovery contract, leading to hallucinated retries or confused responses. Setting failure_error_function lets you control what the model sees, typically a structured JSON describing the failure and what input to try instead.
|
|
Run trustabl/trustabl-action@v0:
src/opencmo/tools/ai_crawler_check.py#L250
When a tool raises an exception, the OpenAI Agents SDK surfaces the exception's string representation to the model by default. The model receives an opaque error with no recovery contract, leading to hallucinated retries or confused responses. Setting failure_error_function lets you control what the model sees, typically a structured JSON describing the failure and what input to try instead.
|
|
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
background
wait
wait-all
cancel
parallel
Loading