pydantic-ai-trustabl
Scan an agent repository for reliability and safety weaknesses from inside a Pydantic AI agent, and hand the findings back for the agent to fix.
pip install pydantic-ai-trustabl
The problem
Trustabl analyses agent code: unsafe tool grants, missing turn limits, untyped tools, prompt-injectable shell tools, fetch calls with no timeout. It ships as a CLI and as editor plugins. There was no way to give a Pydantic AI agent the same scan-and-fix loop from your own code.
The solution
Trustabl adds a scan_repository tool that runs the scanner in the run's
workspace, summarises the report, and returns it. The agent then verifies each
finding and fixes the real ones with whatever tools it already has.
from pydantic_ai import Agent
from pydantic_ai.capabilities import LocalWorkspace
from pydantic_ai_trustabl import Trustabl
agent = Agent(
'anthropic:claude-sonnet-5',
capabilities=[
LocalWorkspace('.'),
Trustabl(),
],
)
result = agent.run_sync('Scan this repository and fix the confirmed findings.')
print(result.output)
Why it summarises
A full scan of a large agent repository reaches several megabytes, far past what
is useful in a tool result. The tool returns the inventory, a severity histogram,
and the findings above a floor, with truncated set when any were dropped.
Two details worth knowing:
- Test-path findings are excluded, from the returned findings and from the
histogram. The scanner classifies them with
origin: test. Counting them would produce a histogram that contradicts the findings printed beside it. rules_skippedis reported. When the rule pack is newer than the scanner, rules are skipped silently. A zero finding count with a non-zerorules_skippedmeans the scan was incomplete, not that the code is clean.
Options
| Option | Default | What it does |
|---|---|---|
command |
None |
Binary name or path. None resolves it automatically |
engine_version |
0.1.13 |
Scanner release to download when none is on PATH |
severity_floor |
medium |
Lowest severity returned. Counts ignore the floor |
max_findings |
50 |
Cap on returned findings, worst first |
timeout |
600.0 |
Seconds allowed for one scan |
guidance |
None |
Replaces the default instructions. '' contributes none |
How the scanner is found
- If
trustablis on the workspace's PATH, that is used. - Otherwise the pinned release is downloaded and its SHA-256 checked against
the release's
checksums.txt. Nothing is executed before the checksum matches. - A host download is invisible to a sandbox, so the capability confirms the workspace can see the binary and otherwise raises with install instructions.
The version is pinned rather than tracking latest, so checksum verification stays meaningful and a bad scanner release cannot reach every user at once.
Privacy
The scan runs where your agent runs. There is no hosted scanner, no account, no code upload, and no model in the analysis path. The only network calls are fetching the scanner on first use and the versioned rule pack at scan time.
Links
Apache-2.0
Metadata
Release files for pydantic-ai-trustabl 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pydantic_ai_trustabl-0.1.0.tar.gz | 14.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pydantic_ai_trustabl-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.8 kB
Release files / pydantic_ai_trustabl-0.1.0.tar.gz
| Download URL | pydantic_ai_trustabl-0.1.0.tar.gz |
|---|---|
| Size | 14.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4a50c8f02aa499a2413376fc7056b7c99f16edd120f8e9ed1f55a325047f0f4f
|
|
BLAKE2b-256 checksum How to use checksums |
bba5762a7385343c57b216ed74932563fbc1940169fe1aec8813fc9254e7c818
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / pydantic_ai_trustabl-0.1.0-py3-none-any.whl
| Download URL | pydantic_ai_trustabl-0.1.0-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7af6984baa35fc2758be7e23b473311feb860094e0cc31b536c95bfc20599b85
|
|
BLAKE2b-256 checksum How to use checksums |
9fbcfe523a7b9bbba0e1d76fa95a572b08745d226dc105d196ee4f33ea2fecd4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log