Metal Mantra / AGENT INTELLIGENCEPublic evidence reportAUTOMATED SIGNAL. NOT CERTIFICATION.
PUBLIC REPORT / AGENT SIGNAL v0.2

pydantic-ai.

Automated source and domain checks for pydantic/pydantic-ai.

Inspect GitHub source

20.5k starsMITpushed today

0community interest

Votes show community interest, not safety. They never change this score.

AUTOMATED SIGNAL70/100BBBNot security certification
START HERE

Critical findings need attention.

Critical finding · details withheld for 30 days

Inspect the findings
WHAT THIS DOES NOT ESTABLISH

Runtime safety, real-world agent capability, fitness for your use case or independent certification.

Scan scope200 / 916Partial eligible-file selection · not the entire repository
Recorded findings11Heuristic matches requiring human review
SnapshotOct 11, 2026UTC · engine 0.4.0
DNS at scan timeUnverifiedDomain control is not security certification
01 / KNOW THE REPOSITORY

What the source
actually tells us.

Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.

INSPECTED SOURCE200 / 916Partial selection
READMEReadRepository-authored information
MANIFESTS1LICENSE

Who it is for

No explicit purpose, audience or use case was extracted from the inspected README.

What it can do

No explicit capability or integration was extracted; that does not mean none exists.

What adoption takes

No matching setup or dependency statement was extracted from inspected metadata.

Limits and terms

  • Declared license · manifest declares · unreviewed

    A license or copying file is present; its terms have not been reviewed.

    LICENSE:1

Observed technical context

Python · 200 selected filesTool-calling reference · static only

These are references in selected source files, not proof that a feature works at runtime.

Read from commit 69ea1e5 at Oct 11, 2026, 10:32 AM UTC. Source links open that exact commit. Repository statements are unreviewed and do not affect the score.

02 / FINDINGS FIRST

What needs
a closer look.

Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.

Dependencies: 381 exact runtime versions from uv.lock checked against OSV.dev on Oct 11, 2026; 11 with known advisories. Reachability is not checked.

11 findings
CRITICAL

Critical finding · details withheld for 30 days

SEC002 · Security & privacy

Details are withheld from public view for 30 days after the scan. The owner can see them in full.

SUGGESTED ACTION

Review the private assessment and address the finding.

[location embargoed] · location unavailable
CRITICAL

Critical finding · details withheld for 30 days

SEC002 · Security & privacy

Details are withheld from public view for 30 days after the scan. The owner can see them in full.

SUGGESTED ACTION

Review the private assessment and address the finding.

[location embargoed] · location unavailable
MAJOR

Domain ownership not verified

TRUST001 · Entity trust

Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.

SUGGESTED ACTION

Verify the domain using the Metal Mantra DNS TXT challenge.

pydantic.dev · location unavailable
MAJOR

Dependency with a high-severity advisory

DEP001 · Security & privacy

sentence-transformers 5.2.2 (PyPI) has known advisories: GHSA-jhr6-gm9c-rqjv, PYSEC-2026-4164 (highest severity critical). sentence-transformers local model loading bypasses trust_remote_code and executes custom Python

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:6489
MAJOR

Dependency with a high-severity advisory

DEP001 · Security & privacy

cryptography 49.0.0 (PyPI) has known advisories: GHSA-g6cj-pr64-35w5, PYSEC-2026-3552 (highest severity high). cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:67
MAJOR

Dependency with a high-severity advisory

DEP001 · Security & privacy

fsspec 2025.10.0 (PyPI) has a known advisory: GHSA-27vj-qcqg-25rc (highest severity high). fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:1667
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

src/pydantic_ai_harness/pydantic_ai_harness/experimental/acp/_client_toolsets.py:114
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

src/pydantic_ai_harness/pydantic_ai_harness/localstack/_toolset.py:386
MINOR

Dependency with a known advisory

DEP002 · Security & privacy

datasets 4.4.2 (PyPI) has known advisories: GHSA-379c-qx7v-6h59, PYSEC-2026-3716 (highest severity moderate). Hugging Face Datasets folder-based builders allow path traversal through file_name metadata

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:1661
MINOR

Dependency with a known advisory

DEP002 · Security & privacy

mako 1.3.12 (PyPI) has a known advisory: GHSA-5639-2j2p-m4mx (highest severity moderate). Mako: Path traversal via drive-letter URI on Windows in TemplateLookup

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:74
MINOR

Dependency with a known advisory

DEP002 · Security & privacy

multidict 6.7.0 (PyPI) has a known advisory: GHSA-54p9-h82j-f925 (highest severity moderate). Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction

SUGGESTED ACTION

Upgrade to a fixed version listed in the advisory and regenerate the lockfile.

uv.lock:161
03 / EVIDENCE & LIMITS

The boundary
is part of the result.

What was scanned
200 of 916 eligible files · Partial selection.
Supported static source patterns and domain checks; no runtime execution.
What remains unknown
Unscanned files, external dependencies, production configuration, actual agent behavior and evidence beyond the configured checks.
Source location
Links open the current repository HEAD. Source may have changed since this snapshot.
Something looks wrong?
Tell us if a finding, scope or claim on this report needs a correction. Report a problem with this report
Entity trust · 15% of v0.2
Includes DNS ownership, HTTPS and policy evidence. Verification is domain control, not a security certificate.
DNS: unverifiedHTTPS: availablePrivacy: foundTerms: found
04 / THE METHOD BEHIND THE NUMBER

Open the
calculation.

Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.

01

Security & privacy

8 findings · 25% weight
22/1005.5 pts
02

Guardrails & loop control

0 findings · 25% weight
100/10025.0 pts
03

Schema & tooling

2 findings · 20% weight
84/10016.8 pts
04

Token & cost efficiency

0 findings · 15% weight
100/10015.0 pts
05

Entity trust

1 findings · 15% weight
50/1007.5 pts
Inspect the current standard
USER REPORTS

Did pydantic-ai work for people?

No user reports yet.

Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.

Sign in with GitHub to add a report

SHARE THE EVIDENCE

A signal.
Not a seal.

Share the full report so its scope and limits travel with the score.

Metal Mantra automated signal 70/100, not certified