Skip to content

Security Findings in secure-agent-lab #1

Description

@joshua-trustabl

I ran the Trustabl scanner on your repo and found two medium-severity issues. In shopping-assistant/app/agent.py, the LlmAgent has no description, which means Google ADK routes delegation between agents without using this field. Additionally, the Agent has no safety_settings, resulting in Gemini models' content filters being OFF by default. These findings could potentially impact security and functionality if not addressed.


Add Trustabl to your CI — trustabl/trustabl-action:

- name: Trustabl scan
  uses: trustabl/trustabl-action@v1

https://trustabl.ai

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions