pypi
openai
1 versiondiscovered · its AI-security audit & verification record by name.
1.57.0vulnerability foundresolved-commitattested-tag
coverage →openai/openai-python @ 293a4b5c6d7e8f90…
AI security assessmentcleanqwen2.5-7b-instruct
Client SDK: auth headers handled correctly, no request forgery surface found.
Methodology
Sources @ 293a4b5c6d
README.md, src/openai/_client.py, src/openai/_base_client.py, src/openai/resources/chat/completions.py, src/openai/_streaming.py, src/openai/lib/azure.py
Parts 6 files, 11500 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
This audit found an active vulnerability (CWE-502) at this exact commit — do not skip-scan;
signet gatefails this version.classes examined: CWE-502
Gate this package in CI
Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.
signet gate --purl pkg:pypi/openai@1.57.0 --registry https://signet.seekerslab.com
README badge
Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.
