Public AI agent scan brief
huggingface/smolagents AI agent security scan
Partial no-execution triage for the public smolagents repo. This is a heuristic scan of 90 selected public text files, not a commissioned audit, vulnerability disclosure, or security certification. These are not confirmed vulnerabilities.
Top findings
Code-thinking agents need sandbox and secret handling checks
The scan snapshot saw 27,935 stars and review signals around credentials, async or remote examples, and write-capable browser or code paths. A paid review would validate sandbox defaults, tool permissions, provider tokens, and documentation-to-runtime gaps.
Evidence slice
Files that triggered review signals
Credential and workflow signals appeared near `.github/workflows/build_documentation.yml`, `.github/workflows/trufflehog.yml`, `docs/source/en/examples/web_browser.md`, `docs/source/en/tutorials/inspect_runs.md`, and `docs/source/en/tutorials/memory.md`.
Remote and write-action signals appeared in async-agent, secure-code-execution, memory, web-browser, and localized inspect-runs documentation paths.
Paid handoff
Convert this scan into a fixed-scope review
- Confirm the current agent, code-execution, and browser tool surfaces in scope.
- Review sandbox, network, token, memory, and trace boundaries for agent runs.
- Validate redaction, approval, remote runtime, and write-action regression tests.
- Pay USD $1,000 only after written scope acceptance.