Skip to content

feat(tools-registry): add trustabl - #21951

Open
sairenchristianbuerano wants to merge 1 commit into
vercel:mainfrom
trustabl:feat/add-tool-trustabl
Open

sairenchristianbuerano wants to merge 1 commit into
vercel:mainfrom
trustabl:feat/add-tool-trustabl

Conversation

@sairenchristianbuerano

Copy link
Copy Markdown

Background

The AI SDK tools registry has no static-analysis entry. Agents built on the SDK can call out to search, sandboxes and browsers, but nothing lets an agent inspect the reliability and safety of agent code itself — the untyped tools, missing step bounds, unsafe provider shell and file tools, and fetch calls with no timeout that only surface in production.

Trustabl is an Apache-2.0 static analyzer for AI-agent codebases. It reads code, inventories the agents, tools, sub-agents and MCP servers declared in it, and evaluates each against a versioned rule pack. It never executes the agent, and the scan runs on the caller's machine.

Summary

Adds one entry to content/tools-registry/registry.ts for @trustabl/ai-sdk. No other files changed.

Three things a reviewer may want up front:

No API key. There is no hosted service, so apiKeyEnvName and apiKeyUrl are omitted. The package needs no account.

The tool summarises rather than returning the scan. A full scan of a large repository exceeds six megabytes of JSON, past what a model can read. The tool returns the inventory, a severity histogram and the findings above a severity floor, with an explicit flag when the list was capped. A separate scan() export returns the complete result for programmatic use, so the raw document cannot reach a context window by accident.

No binary is bundled. On first use the package downloads the pinned scanner release for the host platform and verifies it against that release's published checksums.txt before anything is executed. TRUSTABL_BIN skips the download entirely for air-gapped environments. Nothing is uploaded; the only network calls are fetching the scanner and its rule pack.

Tags are security and code, both already in use in the registry.

End-to-End Verification

The codeExample was run as written, not just reviewed:

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant