Skip to content

feat(langchain): add LC-103, agent wires a raw HTTP Requests built-in tool - #103

Open
jiaxinaspenlin-dotcom wants to merge 1 commit into
trustabl:mainfrom
jiaxinaspenlin-dotcom:feat/langchain-requests-builtin-tool
Open

feat(langchain): add LC-103, agent wires a raw HTTP Requests built-in tool#103
jiaxinaspenlin-dotcom wants to merge 1 commit into
trustabl:mainfrom
jiaxinaspenlin-dotcom:feat/langchain-requests-builtin-tool

Conversation

@jiaxinaspenlin-dotcom

Copy link
Copy Markdown

Summary

Adds LC-103 for LangChain agents that wire langchain_community's Requests* built-in tools directly into an agent.

These tools provide outbound HTTP capability where the method is fixed by the class but the destination can be model-controlled, creating exposure to internal services, cloud metadata endpoints, localhost/admin interfaces, and other resources reachable from the agent host.

What changed

  • Added LC-103 to langchain/agent_safety.yaml
  • Detects:
    • RequestsGetTool
    • RequestsPostTool
    • RequestsPutTool
    • RequestsPatchTool
    • RequestsDeleteTool
  • Uses the existing agent_uses_hosted_tool_class predicate
  • No new predicate
  • No schema version bump

Rule metadata

  • Rule: LC-103
  • Severity: medium
  • Confidence: 0.75
  • Language: python
  • Scope: agent

Validation

trustabl rules validate ../trustabl-rules

Result:

OK: 85 rule pack(s), 207 rule(s) valid under rule schema version 14

The engine's existing LangChain hosted-tool discovery was also verified to recognize all five Requests* classes without analyzer changes.

Paired changes

All coordinated changes use:

feat/langchain-requests-builtin-tool

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant