Skip to content

v0.2.0

Latest

Choose a tag to compare

@sunilgentyala sunilgentyala released this 28 Sep 02:05
· 1 commit to main since this release

Found by running v0.1.0 against 6 real public agent-framework repositories (see EVALUATION.md).

Added

  • AG004: detects subprocess.*([interpreter, "-c", code], ...) code execution — the same risk class as eval()/exec(), invisible to AG001/AG002. Found in a real llama_index MCP tool integration.
  • .ipynb notebook support: code cells are now scanned by the same rules as .py files. Two real eval()/exec()-on-agent-output findings existed only in notebook cells in public repos and were invisible to v0.1.0.

Fixed

  • Framework/PQC marker matching now uses word-boundary matching instead of plain substring search, closing a false-positive vector (autogen matching inside autogenerated).

30 tests passing (was 22). Full writeup: EVALUATION.md.