You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds LC-103 for LangChain agents that wire langchain_community's Requests* built-in tools directly into an agent.
These tools provide outbound HTTP capability where the method is fixed by the class but the destination can be model-controlled, creating exposure to internal services, cloud metadata endpoints, localhost/admin interfaces, and other resources reachable from the agent host.
What changed
Added LC-103 to langchain/agent_safety.yaml
Detects:
RequestsGetTool
RequestsPostTool
RequestsPutTool
RequestsPatchTool
RequestsDeleteTool
Uses the existing agent_uses_hosted_tool_class predicate
No new predicate
No schema version bump
Rule metadata
Rule: LC-103
Severity: medium
Confidence: 0.75
Language: python
Scope: agent
Validation
trustabl rules validate ../trustabl-rules
Result:
OK: 85 rule pack(s), 207 rule(s) valid under rule schema version 14
The engine's existing LangChain hosted-tool discovery was also verified to recognize all five Requests* classes without analyzer changes.
Paired changes
trustabl/trustabl — engine fixture and fire/silent test coverage
Thanks @jiaxinaspenlin-dotcom. LC-103 fills a real gap: LC-101 covers the REPL and shell built-ins, but the Requests* family was uncovered even though the engine's LangChain hosted-tool discovery already recognizes all five classes, so no analyzer change and no schema bump was the right call. agent_uses_hosted_tool_class is dispatched at agent scope, the three applies_to tokens are all valid for scope: agent, and medium / 0.75 sits sensibly between LC-101 (high / 0.85) and LC-102 (low / 0.6). The explanation names the concrete consequence (metadata endpoint, localhost admin ports, response bodies re-entering the conversation as untrusted text) and the fix prescribes specific changes, both in LangChain's own vocabulary. The fixture mirror in trustabl/trustabl#175 is identical to this hunk line for line, and the rationale doc is already open as trustabl/trustabl-rulebook#79, which is the part that usually goes missing.
Two small things. The rule is appended after LC-111, so the file is no longer in ID order; moving it under LC-102 reads better. And the common RequestsToolkit(...).get_tools() shape does not put the class directly in tools=[...], so this rule will miss that path. That is a discovery gap rather than a bug here, worth a follow-up.
LC-103 is also claimed by #108 and #113, so whichever lands first, the others will need to renumber and rebase.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds LC-103 for LangChain agents that wire
langchain_community'sRequests*built-in tools directly into an agent.These tools provide outbound HTTP capability where the method is fixed by the class but the destination can be model-controlled, creating exposure to internal services, cloud metadata endpoints, localhost/admin interfaces, and other resources reachable from the agent host.
What changed
langchain/agent_safety.yamlRequestsGetToolRequestsPostToolRequestsPutToolRequestsPatchToolRequestsDeleteToolagent_uses_hosted_tool_classpredicateRule metadata
LC-103medium0.75pythonagentValidation
trustabl rules validate ../trustabl-rulesResult:
OK: 85 rule pack(s), 207 rule(s) valid under rule schema version 14The engine's existing LangChain hosted-tool discovery was also verified to recognize all five
Requests*classes without analyzer changes.Paired changes
All coordinated changes use:
feat/langchain-requests-builtin-tool