You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds the engine-side fixture and test coverage for LC-103, which detects LangChain agents that wire langchain_community's Requests* built-in HTTP tools.
Thanks @jiaxinaspenlin-dotcom, this is a clean engine half. I compared the testdata/rules-fixture/langchain/agent_safety.yaml hunk against the one in trustabl/trustabl-rules#103 and it matches line for line, so rules-sync stays green provided the two land together. The three cases follow the LC-101 pattern directly above them, set Language, and the two fire cases exercise different applies_to kinds (ReactAgent resolves to langchain_agent, AgentExecutor to langchain_agent_executor), which is more than the minimum the coverage guard asks for.
Two nits, neither blocking. applies_to also lists langchain_state_graph and nothing covers it, so mirroring LC-101's StateGraph case would close that out. The silent case uses TavilySearchResults, which is not in LangChainHostedToolClasses and so is never emitted as a HostedToolRef by a real scan; it does exercise the class filter, but an agent with no hosted refs would be the shape users actually hit.
Coordination note: LC-103 is also claimed by #183 and #186, so whichever lands first, the others will need to renumber and rebase. That is not a mark against this one.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the engine-side fixture and test coverage for LC-103, which detects LangChain agents that wire
langchain_community'sRequests*built-in HTTP tools.What changed
testdata/rules-fixture/langchain/agent_safety.yamlinternal/rules/policies_test.goCoverage includes:
ReactAgentwithRequestsGetToolAgentExecutorwithRequestsPostToolReactAgentwithTavilySearchResultsEvery
AgentDefsetsLanguage.No analyzer changes were required because the existing LangChain hosted-tool discovery already recognizes all five
Requests*classes.Validation
go vet ./...— passgo test -race ./internal/rules/...— passgo test -race ./...— 26 packages passed, 0 failuresgo build -o /tmp/trustabl ./cmd/trustabl— passcheck-rules-sync.sh— in sync with productionThe fixture is byte-identical to the corresponding rule definition in
trustabl-rules.Paired changes
All coordinated changes use the shared branch:
feat/langchain-requests-builtin-tool