npm

langchain

1 versiondiscovered · its AI-security audit & verification record by name.

0.3.7unauditedresolved-commitverified
coverage →

langchain-ai/langchainjs @ a1b2c3d4e5f60718…/libs/langchain

Audits exist at this commit, but none touch /libs/langchain — they cover other packages in this monorepo, so this package is not audited by them.

AI security assessmentcleanqwen2.5-7b-instruct

JS agent toolkit mirrors the patched Python paths; tool output is not executed.

2026-08-15confidence 78%not a signed attestation — automated pre-screen
Methodology
Sources @ a1b2c3d4e5
README.md, langchain/src/agents/agent.ts, langchain/src/agents/executor.ts, langchain/src/tools/base.ts, langchain/src/chains/base.ts, langchain/src/memory/base.ts
Parts 6 files, 12900 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local

Gate this package in CI

Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.

signet gate --purl pkg:npm/langchain@0.3.7 --registry https://signet.seekerslab.com

README badge

Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.

![signet](https://signet.seekerslab.com/v1/badge/npm/langchain.svg)

← Back to the package dictionary