Found by running v0.1.0 against 6 real public agent-framework repositories (see EVALUATION.md).
Added
AG004: detectssubprocess.*([interpreter, "-c", code], ...)code execution — the same risk class aseval()/exec(), invisible toAG001/AG002. Found in a real llama_index MCP tool integration..ipynbnotebook support: code cells are now scanned by the same rules as.pyfiles. Two realeval()/exec()-on-agent-output findings existed only in notebook cells in public repos and were invisible to v0.1.0.
Fixed
- Framework/PQC marker matching now uses word-boundary matching instead of plain substring search, closing a false-positive vector (
autogenmatching insideautogenerated).
30 tests passing (was 22). Full writeup: EVALUATION.md.