langchain — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited langchain (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Purpose: Prevent common LangChain mistakes — deprecated chain classes, missing retry/timeout guards, unsafe prompt handling, and unobservable pipelines.
|) to compose runnables instead of deprecated constructor-based chain classes (LLMChain, SequentialChain, TransformChain). Reference: ERR-2026-026langchain.chains.llm or langchain.chains.sequential; use langchain_core.runnables and langchain_core.prompts instead.RunnablePassthrough to thread context through a chain without mutation rather than writing a lambda that returns its input unchanged.RunnableParallel over manually calling multiple chains and merging dicts; it expresses intent and enables parallel execution.PydanticOutputParser, JsonOutputParser, StrOutputParser) to chains that produce structured data; never parse raw LLM strings manually downstream.prompt.partial(format_instructions=parser.get_format_instructions()) to bind parser instructions into the prompt template rather than hard-coding them in the template string.ChatPromptTemplate.from_messages([("system", ...), ("human", ...)]) instead of a single PromptTemplate for chat models; mixing roles in one string breaks structured output.ChatOpenAI, ChatAnthropic, or equivalent chat-model classes for new code; the base OpenAI LLM class is deprecated for most use cases and lacks tool-calling support.model="gpt-4o" (or equivalent) so upgrades are intentional.RunnableWithMessageHistory over manual history management or deprecated ConversationChain; it integrates cleanly with LCEL and supports async.session_id key when constructing RunnableWithMessageHistory to prevent cross-user memory leakage in multi-tenant services.@tool decorator (or StructuredTool.from_function) with a typed signature and docstring; never pass raw callables to an agent without a schema.create_tool_calling_agent + AgentExecutor over deprecated initialize_agent; it uses native tool-calling APIs and avoids ReAct string parsing.max_iterations and max_execution_time on AgentExecutor to prevent runaway loops; default is unbounded.retriever | format_docs | prompt | llm | parser rather than RetrievalQA.from_chain_type; the latter is deprecated and hides the retrieval step..lazy_load() over .load() for large corpora to avoid loading all documents into memory at once..with_retry(stop_after_attempt=3, wait_exponential_jitter=True) on any runnable that calls an external API; never let transient rate-limit errors propagate uncaught.request_timeout (or timeout) to chat model constructors; omitting it allows indefinitely hanging requests.callbacks=[LangSmithTracer()] or equivalent on chains in production; never ship a pipeline with no tracing so failures are diagnosable.llm.get_num_tokens(text) or a tiktoken counter to verify the payload fits within the model's context window.set_llm_cache(InMemoryCache()) during development and SQLiteCache in staging to avoid redundant API calls and reduce cost during iteration.skills/python/SKILL.mdskills/error-log/SKILL.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.