C1 Identity & least privilege
Moderate 0.60 / 1.00
The researcher holds no cloud, repository or account credentials. In the default setup it searches DuckDuckGo, which needs no key at all, and talks to a local Ollama model; if the operator switches to Tavily or Perplexity, it uses that service's API key from the environment and nothing else. There are no subprocesses that could inherit the environment and no per-request authorization layer, but there is also very little authority to misuse: a stolen key can only spend search credits.
C2 Approval gates
N/A · full credit 1.00 / 1.00
The researcher has no consequential actions: it only runs web searches, downloads search-result pages and writes a summary into its own run state. It never writes files, sends messages, posts content or calls a write API, so there is nothing for an approval gate to protect. Paid search calls (Tavily, Perplexity, when configured) cost credits, which is bounded by the loop limit scored in C10.
C3 Tool & action scoping
Moderate 0.55 / 1.00
The model never gets a general-purpose tool. The workflow is fixed in code: the model only writes the text of the next search query, and the code decides which search service to call and how many results to take (one to three). When full-page fetching is on, which it is by default, the code downloads every result URL with a 10-second timeout and trims the text to about 4,000 characters, but it applies no host or address restrictions to those URLs. Nothing can write, execute or send.
C4 Code-execution isolation
N/A · full credit 1.00 / 1.00
The researcher never runs model-generated or downloaded text as code. Model output is only parsed as JSON to extract a query string, and downloaded pages are converted to markdown text. There is no shell, eval, subprocess or script execution anywhere in its source.
C5 Untrusted input blast radius
Minimal 0.47 / 1.00
Web pages and search snippets are the researcher's whole input, and they go straight to the model. The code wraps them in simple context tags but nothing acts on those tags. What limits a hijack is the fixed workflow: injected text can change the summary and steer the next search query, but it cannot pick tools, write anything, or reach secrets, because the model never sees credentials and has no actions beyond searching. The remaining outbound channel is the text of search queries sent to the configured search provider.
C6 Memory, context & configuration integrity
N/A · full credit 1.00 / 1.00
Nothing the researcher reads persists into future behaviour. It has no memory store, vector index or instruction files, and it does not load configuration from any workspace it reads. Run state (sources and the running summary) lives in the LangGraph thread for that run. Configuration comes from the operator's environment, the project's own .env, or the run settings in LangGraph Studio.
C7 Third-party extensions
N/A · full credit 1.00 / 1.00
The researcher loads no third-party code at runtime: there are no plugins, MCP servers, downloaded tools or model files that execute code. Models are served by a separate local Ollama or LM Studio process. The quickstart and Docker image launch the LangGraph CLI with `uvx --refresh`, which is the project's own unpinned dependency rather than an extension.
C8 Secrets & sensitive-data protection
Minimal 0.47 / 1.00
API keys come from environment variables and are never placed in prompts, so the model never sees them. There is no redaction or masking code at all: full model responses are printed to the console, and when LangSmith tracing is enabled by the operator, search queries and results are sent to LangSmith. The default setup with DuckDuckGo holds no secret, and any optional key is scoped to one search service.
C9 Audit & traceability
Minimal 0.40 / 1.00
The researcher has no audit log of its own. Its graph state accumulates every search's formatted results and source list, and the LangGraph runtime keeps that state per thread, which lets you see what was searched and fetched in a run. Beyond that, there are console prints and opt-in LangSmith tracing. Nothing records who started a run, and the dev server's storage is not built for durability or tamper resistance.
C10 Limits & kill switch
Moderate 0.55 / 1.00
Research depth is capped in code at three loops by default (four searches in total), and the model cannot change that number; only the operator or the run configuration can. Full-page downloads have a 10-second timeout, but calls to the local model and the Perplexity API have none. There is no token or cost budget and no ceiling on the configurable loop count. Stopping a run uses the LangGraph server's cooperative cancellation.