Who it is for
No explicit purpose, audience or use case was extracted from the inspected README.
Automated source and domain checks for pydantic/pydantic-ai.
Inspect GitHub sourceVotes show community interest, not safety. They never change this score.
Critical finding · details withheld for 30 days
Inspect the findingsRuntime safety, real-world agent capability, fitness for your use case or independent certification.
Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.
No explicit purpose, audience or use case was extracted from the inspected README.
No explicit capability or integration was extracted; that does not mean none exists.
No matching setup or dependency statement was extracted from inspected metadata.
A license or copying file is present; its terms have not been reviewed.
LICENSE:1These are references in selected source files, not proof that a feature works at runtime.
Read from commit 69ea1e5 at Oct 11, 2026, 10:32 AM UTC. Source links open that exact commit. Repository statements are unreviewed and do not affect the score.
Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.
Dependencies: 381 exact runtime versions from uv.lock checked against OSV.dev on Oct 11, 2026; 11 with known advisories. Reachability is not checked.
Details are withheld from public view for 30 days after the scan. The owner can see them in full.
Review the private assessment and address the finding.
Details are withheld from public view for 30 days after the scan. The owner can see them in full.
Review the private assessment and address the finding.
Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.
Verify the domain using the Metal Mantra DNS TXT challenge.
sentence-transformers 5.2.2 (PyPI) has known advisories: GHSA-jhr6-gm9c-rqjv, PYSEC-2026-4164 (highest severity critical). sentence-transformers local model loading bypasses trust_remote_code and executes custom Python
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
cryptography 49.0.0 (PyPI) has known advisories: GHSA-g6cj-pr64-35w5, PYSEC-2026-3552 (highest severity high). cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
fsspec 2025.10.0 (PyPI) has a known advisory: GHSA-27vj-qcqg-25rc (highest severity high). fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.
Parse and validate the result before returning it.
The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.
Parse and validate the result before returning it.
datasets 4.4.2 (PyPI) has known advisories: GHSA-379c-qx7v-6h59, PYSEC-2026-3716 (highest severity moderate). Hugging Face Datasets folder-based builders allow path traversal through file_name metadata
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
mako 1.3.12 (PyPI) has a known advisory: GHSA-5639-2j2p-m4mx (highest severity moderate). Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
multidict 6.7.0 (PyPI) has a known advisory: GHSA-54p9-h82j-f925 (highest severity moderate). Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
Upgrade to a fixed version listed in the advisory and regenerate the lockfile.
Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.
No user reports yet.
Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.
Share the full report so its scope and limits travel with the score.