C1 Identity & least privilege
Minimal 0.00 / 1.00
LangChain has no identity or authorization layer of its own. An agent built with create_agent runs every tool with whatever credentials the developer's code and the host process hold, and nothing checks a tool call against a policy or the requesting user. The one narrowing found is accidental-looking: the opt-in shell tool starts with an empty environment when no env is passed, although its docstring says it inherits the parent environment. If an agent is hijacked, the attacker gets the full authority of the process.
C2 Approval gates
Minimal 0.30 / 1.00
By default create_agent executes every tool call the model emits with no human approval. LangChain ships a good opt-in HumanInTheLoopMiddleware that pauses on listed tools, shows the exact tool name and arguments, and supports approve, edit, reject and respond, with edits applied exactly at execution. But it only gates tools named in its map; any tool not listed, including MCP tools added later, is auto-approved, and nothing offers undo or rollback for actions already taken.
C3 Tool & action scoping
Minimal 0.45 / 1.00
Every LangChain tool with a Pydantic schema has its arguments type-checked before it runs, which stops malformed calls but is not an allowlist. Tools defined with a raw JSON schema, which is how MCP tools are adapted, skip validation entirely. The bundled file-search tool does resolved, symlink-aware path containment, but the bundled shell tool accepts any command string. No tools are enabled unless the developer passes them, but the framework has no read/write tiering of its own.
C4 Code-execution isolation
Minimal 0.33 / 1.00
LangChain's code-execution surface is the opt-in ShellToolMiddleware, and when a developer enables it without choosing a policy it runs a persistent bash shell directly on the host, with no filesystem or network isolation. A Docker execution policy is available that runs commands in a separate container with networking off and the container removed afterwards, and it fails rather than falling back to the host when Docker is missing. That container is stock, though: root inside, default capabilities, no resource limits by default, and the developer's workspace mounted read-write when one is configured. Local MCP servers launched over stdio always run on the host.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Tool results, including web, file and MCP content, are appended to the conversation as tool messages and fed straight back to the model, and nothing in the framework tracks taint, quarantines untrusted text, or disables egress or state-changing tools once untrusted content has been read. MCP tool descriptions are passed to the model verbatim. Because LangChain's own documentation combines untrusted inputs, private data and outbound tools in ordinary use, a successful prompt injection can both leak data and take irreversible actions without a human.
C6 Memory, context & configuration integrity
Minimal 0.40 / 1.00
LangChain loads no instruction files or .env files from the working directory, and by default create_agent keeps state only in memory for a single run. Persistence is opt-in through a LangGraph checkpointer (per conversation thread) or store, and when enabled the saved conversation, including untrusted tool output, is reloaded verbatim with no validation, expiry or review. The opt-in summarization middleware re-injects a model-written summary of earlier turns as a user-role message, so injected text can be laundered into something that looks like the user's own instructions.
C7 Third-party extensions
Minimal 0.28 / 1.00
LangChain's runtime extension path is MCP: the beta MCPAdapter connects to servers the developer names and exposes every tool they advertise. String targets are refused unless they are http(s) URLs, so a string cannot silently launch a local script. But there is no version pinning, hash check, or re-approval when a server's tools or descriptions change between runs, and stdio servers run as local processes under the same user.
C8 Secrets & sensitive-data protection
Minimal 0.45 / 1.00
Model API keys are held as Pydantic SecretStr values and are swapped for secret references when LangChain objects are serialized, and the framework ships no telemetry or crash reporting. The opt-in shell tool starts with an empty environment unless the developer passes one, so it does not inherit API keys through its environment. Nothing redacts secrets or personal data from what is sent to the model by default; PII and output redaction are opt-in, and LangSmith tracing, when switched on, uploads full inputs and outputs.
C9 Audit & traceability
Minimal 0.35 / 1.00
By default the only record of what an agent did is the in-memory message list returned to the caller, which holds each tool call's name, arguments and result but no timestamps, and is lost if the process crashes unless a checkpointer is configured. LangChain integrates with LangSmith tracing, which records structured, nested runs for every model and tool call and ships them off the machine, but it is opt-in via environment variables and does not record who requested or approved an action.
C10 Limits & kill switch
Minimal 0.25 / 1.00
create_agent sets LangGraph's recursion limit to 9,999 steps, which is an iteration cap in name only, and there is no default wall-clock, token or cost limit. Opt-in middleware can cap model calls and tool calls per run or per thread, but their limits default to none. A sub-agent built with create_agent gets its own fresh 9,999-step limit. The shell tool does enforce a 30-second per-command timeout and kills the whole process group when it fires.