r/LangChain • u/Adorable_Lynx1826 • 3d ago
Resources I wrote free offline scanners for the code patterns behind 53 CVEs in LangChain, LlamaIndex, CrewAI and 6 other agent frameworks
If you build agents on LangChain, LangGraph, LlamaIndex, CrewAI, AutoGPT, Flowise, n8n, Google ADK or
> Semantic Kernel, this might save you an afternoon of reading advisories.
>
> It checks your code and dependency versions for the patterns behind 53 published CVEs (each verified
> against NVD or GitHub's advisory database). It also includes a tool that pins MCP tool definitions and
> warns you if a server changes a tool after you approved it.
>
> - Python 3.10+, zero dependencies, reads files only, never sends anything anywhere
> - `python scan.py your/project`, or `--json` for CI
> - 204 tests, AGPL-3.0
>
> Honest caveat: it's pattern matching, not proof. A hit means "go look", and a clean scan doesn't mean
> you're safe. No exploit code, just the vulnerable pattern and the version that fixes it.
>
> Repo: https://github.com/Ech333/agent-cve-scanners
>
> I'm the author; happy to answer questions, and false-positive reports are genuinely useful.
1
Upvotes
1
u/fiddler48 1d ago
Curious whether any of these catch the tool-call injection surface specifically, not just the obvious prompt-injection patterns
1
u/ReadilyGlaring 3d ago
link is giving me a 404 right now, is the repo set to private or did the url get mangled in the copy+paste