Security
Secrets, execution and injection sinks
openai / openai-agents-js
6 rule matches across 80 source files. This is a static snapshot—not a review of runtime behavior or a security certification.
Not a GAAAS certification · scanned October 4, 2026
Each pillar is worth 25 points. Deductions follow matched rules and are capped per pillar.
Secrets, execution and injection sinks
Loops, token limits and rate controls
Runtime validation of model output
System context and sensitive logging
Locations point to the public repository. Source snippets are omitted to avoid republishing exposed credentials.
Prompts or model context may be written to application logs.
Prompts or model context may be written to application logs.
Technical details are embargoed until 2026-11-03 to allow remediation.
LLM request does not declare an output-token ceiling.
LLM output is consumed without an explicit runtime schema.
Raw model-generated text is returned to a caller without validation.
This badge identifies an automated code signal. Only a current signed certificate may use the GAAAS Verified mark.
[](https://gaaas.thanhdan.dev/agents/openai/openai-agents-js)