feat(tools-registry): add trustabl - #21951
Open
sairenchristianbuerano wants to merge 1 commit into
Open
sairenchristianbuerano wants to merge 1 commit into
sairenchristianbuerano wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
The AI SDK tools registry has no static-analysis entry. Agents built on the SDK can call out to search, sandboxes and browsers, but nothing lets an agent inspect the reliability and safety of agent code itself — the untyped tools, missing step bounds, unsafe provider shell and file tools, and fetch calls with no timeout that only surface in production.
Trustabl is an Apache-2.0 static analyzer for AI-agent codebases. It reads code, inventories the agents, tools, sub-agents and MCP servers declared in it, and evaluates each against a versioned rule pack. It never executes the agent, and the scan runs on the caller's machine.
Summary
Adds one entry to
content/tools-registry/registry.tsfor@trustabl/ai-sdk. No other files changed.Three things a reviewer may want up front:
No API key. There is no hosted service, so
apiKeyEnvNameandapiKeyUrlare omitted. The package needs no account.The tool summarises rather than returning the scan. A full scan of a large repository exceeds six megabytes of JSON, past what a model can read. The tool returns the inventory, a severity histogram and the findings above a severity floor, with an explicit flag when the list was capped. A separate
scan()export returns the complete result for programmatic use, so the raw document cannot reach a context window by accident.No binary is bundled. On first use the package downloads the pinned scanner release for the host platform and verifies it against that release's published
checksums.txtbefore anything is executed.TRUSTABL_BINskips the download entirely for air-gapped environments. Nothing is uploaded; the only network calls are fetching the scanner and its rule pack.Tags are
securityandcode, both already in use in the registry.End-to-End Verification
The
codeExamplewas run as written, not just reviewed: