GAAAS / AUTONOMOUS AGENT TRUST REGISTRYLegacy automated code signal · archiveCODE SIGNAL ≠ CERTIFICATION
← Back to code signals AUTOMATED CODE SIGNAL v1

langchain-ai / langgraph

langgraph.

2 rule matches across 76 source files. This is a static snapshot—not a review of runtime behavior or a security certification.

AUTOMATED CODE SIGNAL
87/100
PASSED

Not a GAAAS certification · scanned October 4, 2026

76 source files checked2 findingsPARTIAL scan scopeStatic audit · manual review recommended

Where it stands.

Each pillar is worth 25 points. Deductions follow matched rules and are capped per pillar.

01

Security

Secrets, execution and injection sinks

25/25
02

Cost guardrails

Loops, token limits and rate controls

20/25
03

Schema quality

Runtime validation of model output

17/25
04

Transparency

System context and sensitive logging

25/25

What the scan found.

Locations point to the public repository. Source snippets are omitted to avoid republishing exposed credentials.

MAJORSCHEMA QUALITY

Missing structured-output schema

LLM output is consumed without an explicit runtime schema.

FIXDefine a Zod, JSON Schema, Pydantic, or provider-native structured-output schema.
libs/cli/js-examples/src/agent/graph.ts:50 ↗

Show the signal—accurately.

This badge identifies an automated code signal. Only a current signed certificate may use the GAAAS Verified mark.

GAAAS automated code signal 87 out of 100; not certified[![GAAAS Code Signal](https://gaaas.thanhdan.dev/api/v1/badge/langchain-ai/langgraph.svg)](https://gaaas.thanhdan.dev/agents/langchain-ai/langgraph)