Who it is for
No explicit purpose, audience or use case was extracted from the inspected README.
Automated source and domain checks for langchain-ai/langgraph.
Inspect GitHub sourceVotes show community interest, not safety. They never change this score.
Critical finding · details withheld for 30 days
Inspect the findingsRuntime safety, real-world agent capability, fitness for your use case or independent certification.
Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.
No explicit purpose, audience or use case was extracted from the inspected README.
LangGraph provides low-level supporting infrastructure for any long-running, stateful workflow or agent:
README.md:37Durable execution — Build agents that persist through failures and can run for extended periods, automatically resuming from exactly where they left off.
README.md:39Human-in-the-loop — Seamlessly incorporate human oversight by inspecting and modifying agent state at any point during execution.
README.md:40No matching setup or dependency statement was extracted from inspected metadata.
A license or copying file is present; its terms have not been reviewed.
LICENSE:1These are references in selected source files, not proof that a feature works at runtime.
Observed in the scanned archive at Oct 9, 2026, 2:19 PM UTC. Archive digest sha256:20aff1e275c9ab80…. Source links open current GitHub HEAD and may differ from the scan. Repository statements are unreviewed and do not affect the score.
Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.
Details are withheld from public view for 30 days after the scan. The owner can see them in full.
Review the private assessment and address the finding.
A model request does not set a maximum output length. One unusual input can produce a very long, expensive response.
Set max_tokens or the provider's equivalent on each model call.
Model output is used without being checked against a schema. Unexpected or malformed output can break later steps or be trusted when it should not be.
Validate model output with Zod, JSON Schema, Pydantic or provider structured output.
A model call has no visible fallback. If the provider fails or is rate limited, the whole agent fails with it.
Configure a secondary model or explicit fallback path for provider failures.
Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.
Verify the domain using the Metal Mantra DNS TXT challenge.
No privacy policy link was found on the stated homepage. Buyers cannot see how the vendor handles their data.
Expose a clear Privacy Policy link on the official homepage.
No terms link was found on the stated homepage. Buyers cannot see the conditions that apply to using the service.
Expose a clear Terms link on the official homepage.
Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.
No user reports yet.
Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.
Share the full report so its scope and limits travel with the score.