Metal Mantra / AGENT INTELLIGENCEPublic evidence reportAUTOMATED SIGNAL. NOT CERTIFICATION.
PUBLIC REPORT / AGENT SIGNAL v0.2

crewai.

Scanned repository says: For organizations that need a commercial control plane around CrewAI, CrewAI AMP Suite adds managed deployment, observability, governance, security, and enterprise support.

Inspect GitHub source

59.5k starsMITpushed today

0community interest

Votes show community interest, not safety. They never change this score.

AUTOMATED SIGNAL77/100BBBNot security certification
START HERE

Review findings need attention.

LLM request without token ceiling

Inspect the findings
WHAT THIS DOES NOT ESTABLISH

Runtime safety, real-world agent capability, fitness for your use case or independent certification.

Scan scope187 / 953Partial eligible-file selection · not the entire repository
Recorded findings8Heuristic matches requiring human review
SnapshotOct 11, 2026UTC · engine 0.3.0
DNS at scan timeUnverifiedDomain control is not security certification
01 / KNOW THE REPOSITORY

What the source
actually tells us.

Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.

INSPECTED SOURCE200 / 953Partial selection
READMEReadRepository-authored information
MANIFESTS2LICENSE, pyproject.toml

Who it is for

  • Stated purpose · repository says · unreviewed

    For organizations that need a commercial control plane around CrewAI, CrewAI AMP Suite adds managed deployment, observability, governance, security, and enterprise support.

    README.md:69
  • Stated use case · repository says · unreviewed

    You can test different real life examples of AI crews in the CrewAI-examples repo:

    README.md:408
  • Stated purpose · repository says · unreviewed

    You can try one part of the suite, the Crew Control Plane, for free.

    README.md:71
  • Stated use case · repository says · unreviewed

    Landing Page Generator

    README.md:410
  • Stated use case · repository says · unreviewed

    Having Human input on the execution

    README.md:411

What it can do

  • Stated capability · repository says · unreviewed

    Crews for autonomy: Model teams of specialized AI agents with roles, goals, tools, and tasks.

    README.md:396
  • Stated capability · repository says · unreviewed

    Flows for control: Build event-driven workflows with state, branching, routing, and production logic.

    README.md:397
  • Stated capability · repository says · unreviewed

    Seamless integration: Combine Crews and Flows to create complex, real-world automations.

    README.md:398

What adoption takes

  • Stated deployment · repository says · unreviewed

    Setup and run your first CrewAI agents by following this tutorial.

    README.md:154
  • Stated deployment · repository says · unreviewed

    CrewAI uses UV for dependency management and package handling. If you haven't installed uv yet, install it first.

    README.md:202

Limits and terms

  • Declared license · manifest declares · unreviewed

    A license or copying file is present; its terms have not been reviewed.

    LICENSE:1

Observed technical context

Python · 200 selected filesAgent orchestration reference · static onlyModel API reference · static only

These are references in selected source files, not proof that a feature works at runtime.

Read from commit 6b93fa0 at Oct 11, 2026, 10:14 AM UTC. Source links open that exact commit. Repository statements are unreviewed and do not affect the score.

02 / FINDINGS FIRST

What needs
a closer look.

Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.

8 findings
MAJOR

LLM request without token ceiling

REL001 · Guardrails & loop control

A model request does not set a maximum output length. One unusual input can produce a very long, expensive response.

SUGGESTED ACTION

Set max_tokens or the provider's equivalent on each model call.

lib/crewai-tools/src/crewai_tools/tools/ai_mind_tool/ai_mind_tool.py:93
MAJOR

LLM output without runtime schema

SCH001 · Schema & tooling

Model output is used without being checked against a schema. Unexpected or malformed output can break later steps or be trusted when it should not be.

SUGGESTED ACTION

Validate model output with Zod, JSON Schema, Pydantic or provider structured output.

lib/crewai-tools/src/crewai_tools/tools/ai_mind_tool/ai_mind_tool.py:93
MAJOR

Model call without fallback

EFF001 · Token & cost efficiency

A model call has no visible fallback. If the provider fails or is rate limited, the whole agent fails with it.

SUGGESTED ACTION

Configure a secondary model or explicit fallback path for provider failures.

lib/crewai-tools/src/crewai_tools/tools/ai_mind_tool/ai_mind_tool.py:93
MAJOR

Domain ownership not verified

TRUST001 · Entity trust

Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.

SUGGESTED ACTION

Verify the domain using the Metal Mantra DNS TXT challenge.

crewai.com · location unavailable
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

lib/cli/src/crewai_cli/remote_template/main.py:216
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

lib/crewai-tools/src/crewai_tools/rag/loaders/utils.py:39
MINOR

Privacy Policy link not confirmed

TRUST003 · Entity trust

No privacy policy link was found on the stated homepage. Buyers cannot see how the vendor handles their data.

SUGGESTED ACTION

Expose a clear Privacy Policy link on the official homepage.

crewai.com · location unavailable
MINOR

Terms link not confirmed

TRUST004 · Entity trust

No terms link was found on the stated homepage. Buyers cannot see the conditions that apply to using the service.

SUGGESTED ACTION

Expose a clear Terms link on the official homepage.

crewai.com · location unavailable
03 / EVIDENCE & LIMITS

The boundary
is part of the result.

What was scanned
187 of 953 eligible files · Partial selection.
Supported static source patterns and domain checks; no runtime execution.
What remains unknown
Unscanned files, external dependencies, production configuration, actual agent behavior and evidence beyond the configured checks.
Source location
Links open the current repository HEAD. Source may have changed since this snapshot.
Something looks wrong?
Tell us if a finding, scope or claim on this report needs a correction. Report a problem with this report
Entity trust · 15% of v0.2
Includes DNS ownership, HTTPS and policy evidence. Verification is domain control, not a security certificate.
DNS: unverifiedHTTPS: availablePrivacy: not confirmedTerms: not confirmed
04 / THE METHOD BEHIND THE NUMBER

Open the
calculation.

Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.

01

Security & privacy

0 findings · 25% weight
100/10025.0 pts
02

Guardrails & loop control

1 findings · 25% weight
88/10022.0 pts
03

Schema & tooling

3 findings · 20% weight
68/10013.6 pts
04

Token & cost efficiency

1 findings · 15% weight
86/10012.9 pts
05

Entity trust

3 findings · 15% weight
25/1003.8 pts
Inspect the current standard
USER REPORTS

Did crewai work for people?

No user reports yet.

Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.

Sign in with GitHub to add a report

SHARE THE EVIDENCE

A signal.
Not a seal.

Share the full report so its scope and limits travel with the score.

Metal Mantra automated signal 77/100, not certified