GAAAS / AUTONOMOUS AGENT TRUST REGISTRYLegacy automated code signal · archiveCODE SIGNAL ≠ CERTIFICATION
← Back to code signals AUTOMATED CODE SIGNAL v1

openai / openai-agents-js

openai-agents-js.

6 rule matches across 80 source files. This is a static snapshot—not a review of runtime behavior or a security certification.

AUTOMATED CODE SIGNAL
62/100
WARNING

Not a GAAAS certification · scanned October 4, 2026

80 source files checked6 findingsPARTIAL scan scopeStatic audit · manual review recommended

Where it stands.

Each pillar is worth 25 points. Deductions follow matched rules and are capped per pillar.

01

Security

Secrets, execution and injection sinks

25/25
02

Cost guardrails

Loops, token limits and rate controls

5/25
03

Schema quality

Runtime validation of model output

13/25
04

Transparency

System context and sensitive logging

19/25

What the scan found.

Locations point to the public repository. Source snippets are omitted to avoid republishing exposed credentials.

CRITICALCOST GUARDRAILS

Critical finding under coordinated disclosure

Technical details are embargoed until 2026-11-03 to allow remediation.

FIXThe maintainer has been given a remediation window before edited details are published.
[location embargoed]:0 ↗
MAJORCOST GUARDRAILS

Missing token limit

LLM request does not declare an output-token ceiling.

FIXSet max_tokens, maxOutputTokens, or the provider-equivalent limit on every request.
examples/ai-sdk-ui/scripts/ai-sdk.ts:6 ↗
MAJORSCHEMA QUALITY

Missing structured-output schema

LLM output is consumed without an explicit runtime schema.

FIXDefine a Zod, JSON Schema, Pydantic, or provider-native structured-output schema.
examples/ai-sdk-ui/scripts/ai-sdk.ts:6 ↗

Show the signal—accurately.

This badge identifies an automated code signal. Only a current signed certificate may use the GAAAS Verified mark.

GAAAS automated code signal 62 out of 100; not certified[![GAAAS Code Signal](https://gaaas.thanhdan.dev/api/v1/badge/openai/openai-agents-js.svg)](https://gaaas.thanhdan.dev/agents/openai/openai-agents-js)