8RR8← All audits

Audit Report

gpt-engineer-org/gpt-engineer

a90fcd543eed · ran in 27.5s · bundle bef7df2c

Deterministic · 15 ambiguous skipped
Complete audit →

Overall score

1.8 /4

Partial

Risk class

HIGH

4

Code passed

15 / 45

Attestation Yes

0

Outstanding ext.

1

Overall completion status
Code findings on the left; user-attested external evidence on the right.
45

CODE-CHECKED CLAUSES

  • Strong11
  • Adequate4
  • Partial10
  • Inadequate4
  • Absent16
0

ATTESTATION QUESTIONS

  • Yes0
  • No0
  • Not Applicable0
  • Outstanding0

Harm

Don't hurt people

1.7/4

Partial

Truth

Don't deceive people

1.5/4

Partial

Responsibility

Don't abuse power

1.8/4

Partial

Order

Don't destabilize society

2.2/4

Partial

1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →

Safety

Don't harm people
1.3/4Inadequate8 clauses
INADEQUATE
Risk management system established, implemented, documented EU AI Act, Art 9
skip
1/3 rules

1/4

Why we flagged it

Composite raw score 0.30 (1/3 rules matched). Supporting docs may exist outside the repo.

Confidence
95%
Evidence · 1 hit— click to view code
.github/workflows/ci.yaml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • presence_of_threat_model
ADEQUATE
Appropriate level of accuracy declared and tested EU AI Act, Art 15(1)
skip
2/3 rules

3/4

Why we flagged it

Composite raw score 0.70 (2/3 rules matched).

Confidence
95%
Evidence · 3 hits— click to view code
evals/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/ci.yaml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented
INADEQUATE
Resilience to errors, faults, inconsistencies EU AI Act, Art 15(4)
0/3 rules

1/4

Why we flagged it

Composite raw score 0.16 (0/3 rules matched).

Confidence
81%
Evidence · 2 hits— click to view code
pyproject.toml
manifest_framework_dep
View on GitHub →

LangChain

pyproject.toml
manifest_framework_dep
View on GitHub →

Anthropic SDK

Suggested fix · we looked for these and found none

  • error_handling_at_tool_boundaries
  • retry_logic
  • fallback_behaviour
ABSENT
Risks and benefits to people identified NIST AI RMF, Art MAP 3.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • presence_of_threat_model
ADEQUATE
AI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3
skip
2/3 rules

3/4

Why we flagged it

Composite raw score 0.70 (2/3 rules matched).

Confidence
95%
Evidence · 3 hits— click to view code
evals/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/ci.yaml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented
ABSENT
Data protection impact assessment (DPIA) GDPR, Art 35
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_dpia
ABSENT
AI risk assessment process ISO/IEC 42001, Art 6.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_assessment_methodology_documented
PARTIAL
Operational planning and control ISO/IEC 42001, Art 8.1
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
.github/workflows/
presence_of_ci_workflows
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_runbook

Privacy

Respect boundaries
2.4/4Partial6 clauses
STRONG
Untargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_face_image_scraping
STRONG
Emotion recognition in workplace and education EU AI Act, Art 5(1)(f)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_emotion_recognition_in_workplace_education
EXTERNAL
Real-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)
EXT

Why we flagged it

Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.

Confidence
100%
ABSENT
Data and data governance practices documented EU AI Act, Art 10
0/3 rules

0/4

Why we flagged it

Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 1 hit— click to view code
scripts/test_api.py:25
http_external_io
View on GitHub →
""" response = requests.post(url, json=extra_arguments) return response if __name__ == "__main__": URL_BASE = "http://127.0.0

Suggested fix · we looked for these and found none

  • presence_of_data_card
  • data_loading_code_quality
  • bias_evaluation_present
ABSENT
Privacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.8
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • pii_redaction_present
  • privacy_documentation
STRONG
Data protection by design and by default GDPR, Art 25
2/2 rules

4/4

Why we flagged it

Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%
Evidence · 2 hits— click to view code
gpt_engineer/applications/cli/collect.py:138
pseudonymisation_or_anonymisation
View on GitHub →
hashlib.sha256
README.md
default_minimal_data_collection
View on GitHub →

Transparency

Don't deceive people
1.5/4Partial4 clauses
STRONG
Subliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_manipulative_prompt_patterns
ABSENT
Transparent operation and instructions for use EU AI Act, Art 13
0/3 rules

0/4

Why we flagged it

Composite raw score 0.13 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
78%
Evidence · 3 hits— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

README.md
output_interpretation_guidance
View on GitHub →
README.md
limitations_section_present
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_deployer_instructions
  • output_interpretation_guidance
  • limitations_section_present
PARTIAL
Users informed they are interacting with an AI EU AI Act, Art 50(1)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.40 (1/2 rules matched).

Confidence
100%
Evidence · 2 hits— click to view code
README.md
ai_disclosure_in_user_facing_strings
View on GitHub →
gpt_engineer/core/prompt.py
persona_not_human_impersonating
View on GitHub →

Suggested fix · we looked for these and found none

  • ai_disclosure_in_user_facing_strings
ABSENT
Principles relating to processing of personal data GDPR, Art 5
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_privacy_policy
  • purpose_limitation_documented

Auditability

Actions must be traceable
1.5/4Partial8 clauses
ABSENT
Technical documentation drawn up before placing on market EU AI Act, Art 11
0/3 rules

0/4

Why we flagged it

Composite raw score 0.07 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
73%
Evidence · 1 hit— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

Suggested fix · we looked for these and found none

  • presence_of_model_card
  • readme_quality
  • architecture_docs
PARTIAL
Automatic recording of events over the lifetime EU AI Act, Art 12(1)
skip
1/3 rules

2/4

Why we flagged it

Composite raw score 0.48 (1/3 rules matched).

Confidence
100%
Evidence · 7 hits— click to view code
gpt_engineer/core/ai.py:118
log_at_tool_boundary
View on GitHub →
odel_name) logger.debug(f"Using model {self.model_name}") def start(self, system: str, user: Any, *, step_name: str) -> List[M
gpt_engineer/core/ai.py:235
log_at_tool_boundary
View on GitHub →
t=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".join([m.pretty_repr() for m in messages
gpt_engineer/core/ai.py:249
log_at_tool_boundary
View on GitHub →
d(response) logger.debug(f"Chat completion finished: {messages}") return messages @backoff.on_exception(backoff.expo,
gpt_engineer/core/ai.py:421
log_at_tool_boundary
View on GitHub →
t=prompt)) logger.debug(f"Creating a new chat completion: {messages}") msgs = self.serialize_messages(messages) py
gpt_engineer/core/ai.py:435
log_at_tool_boundary
View on GitHub →
=response)) logger.debug(f"Chat completion finished: {messages}") return messages

…and 2 more.

Suggested fix · we looked for these and found none

  • structured_logging_imported
  • logging_persistent_sink
PARTIAL
Logging ensures traceability appropriate to risk EU AI Act, Art 12(2)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.57 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 8 hits— click to view code
gpt_engineer/applications/cli/main.py:30
import_logging
View on GitHub →
difflib import json import logging import os import platform import subprocess import sys from pathlib import Path import openai import ty
gpt_engineer/core/ai.py:19
import_logging
View on GitHub →
ations import json import logging import os from pathlib import Path from typing import Any, List, Optional, Union import backoff import
gpt_engineer/core/ai.py:118
log_at_tool_boundary
View on GitHub →
odel_name) logger.debug(f"Using model {self.model_name}") def start(self, system: str, user: Any, *, step_name: str) -> List[M
gpt_engineer/core/ai.py:235
log_at_tool_boundary
View on GitHub →
t=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".join([m.pretty_repr() for m in messages
gpt_engineer/core/ai.py:249
log_at_tool_boundary
View on GitHub →
d(response) logger.debug(f"Chat completion finished: {messages}") return messages @backoff.on_exception(backoff.expo,

…and 3 more.

Suggested fix · we looked for these and found none

  • logs_include_request_id
INADEQUATE
Context of use established and understood NIST AI RMF, Art MAP 1.1
0/2 rules

1/4

Why we flagged it

Composite raw score 0.15 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 2 hits— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

README.md
output_interpretation_guidance
View on GitHub →

Suggested fix · we looked for these and found none

  • intended_use_documented
  • deployment_context_documented
INADEQUATE
Post-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.1
skip
1/4 rules

1/4

Why we flagged it

Composite raw score 0.36 (1/4 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
gpt_engineer/core/ai.py:33
human_in_loop
View on GitHub →
AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_to_dict, ) from langchain_anthropic import ChatAnt
gpt_engineer/core/ai.py:44
human_in_loop
View on GitHub →
= Union[AIMessage, HumanMessage, SystemMessage] # Set up logging logger = logging.getLogger(__name__) class AI: """ A class that
gpt_engineer/core/ai.py:141
human_in_loop
View on GitHub →
ystem), HumanMessage(content=user), ] return self.next(messages, step_name=step_name) def _extract_content(
gpt_engineer/core/ai.py:233
human_in_loop
View on GitHub →
messages.append(HumanMessage(content=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".
gpt_engineer/core/ai.py:284
human_in_loop
View on GitHub →
e(content="Hello"), HumanMessage(content="How's the weather?")] >>> response = backoff_inference(messages) """ retur

…and 1 more.

Suggested fix · we looked for these and found none

  • feedback_capture_present
  • structured_logging_imported
  • versioning_visible
ABSENT
Records of processing activities GDPR, Art 30
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_processing_register
ADEQUATE
Documented information for the AI management system ISO/IEC 42001, Art 7.5
skip
1/2 rules

3/4

Why we flagged it

Composite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 2 hits— click to view code
README.md
presence_of_versioned_docs
View on GitHub →
.github/workflows/release.yaml
docs_changelog_present
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_versioned_docs
ADEQUATE
Monitoring, measurement, analysis and evaluation ISO/IEC 42001, Art 9.1
2/2 rules

3/4

Why we flagged it

Composite raw score 0.75 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
85%
Evidence · 3 hits— click to view code
evals/
presence_of_eval_suite
View on GitHub →
gpt_engineer/applications/cli/main.py:30
structured_logging_present
View on GitHub →
difflib import json import logging import os import platform import subprocess import sys from pathlib import Path import openai import ty
gpt_engineer/core/ai.py:19
structured_logging_present
View on GitHub →
ations import json import logging import os from pathlib import Path from typing import Any, List, Optional, Union import backoff import

Accountability

Don't abuse power
2.0/4Partial6 clauses
PARTIAL
Deployer log-retention capability supported EU AI Act, Art 26(6)
skip
1/1 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
gpt_engineer/applications/cli/main.py:30
import_logging
View on GitHub →
difflib import json import logging import os import platform import subprocess import sys from pathlib import Path import openai import ty
gpt_engineer/core/ai.py:19
import_logging
View on GitHub →
ations import json import logging import os from pathlib import Path from typing import Any, List, Optional, Union import backoff import
ABSENT
Risk management process documented and accountable NIST AI RMF, Art GOVERN 1.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_owner_assignment
PARTIAL
Ongoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
.github/workflows/ci.yaml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • drift_monitoring_present
ABSENT
Leadership and commitment for AI management ISO/IEC 42001, Art 5.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_ai_policy
  • leadership_signoff_evidence
STRONG
Roles, responsibilities and authorities ISO/IEC 42001, Art 5.3
1/1 rules

4/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%
Evidence · 1 hit— click to view code
.github/CODEOWNERS
presence_of_raci_or_owners
View on GitHub →
STRONG
Internal organization controls ISO/IEC 42001, Art A.5
1/1 rules

4/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%
Evidence · 1 hit— click to view code
.github/CODEOWNERS
presence_of_codeowners
View on GitHub →

Human Oversight

Humans stay in control
1.6/4Partial5 clauses
PARTIAL
Effective human oversight designed and built-in EU AI Act, Art 14(1)
skip
1/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (1/3 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
gpt_engineer/core/ai.py:33
human_in_loop
View on GitHub →
AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_to_dict, ) from langchain_anthropic import ChatAnt
gpt_engineer/core/ai.py:44
human_in_loop
View on GitHub →
= Union[AIMessage, HumanMessage, SystemMessage] # Set up logging logger = logging.getLogger(__name__) class AI: """ A class that
gpt_engineer/core/ai.py:141
human_in_loop
View on GitHub →
ystem), HumanMessage(content=user), ] return self.next(messages, step_name=step_name) def _extract_content(
gpt_engineer/core/ai.py:233
human_in_loop
View on GitHub →
messages.append(HumanMessage(content=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".
gpt_engineer/core/ai.py:284
human_in_loop
View on GitHub →
e(content="Hello"), HumanMessage(content="How's the weather?")] >>> response = backoff_inference(messages) """ retur

…and 1 more.

Suggested fix · we looked for these and found none

  • oversight_ui_present
  • tool_calls_have_dry_run
ABSENT
Interrupt / stop function reachable by overseer EU AI Act, Art 14(4)(d)
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • kill_switch_present
  • graceful_shutdown_handler
PARTIAL
Ability to override / reverse the system's output EU AI Act, Art 14(4)(e)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.60 (1/2 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
gpt_engineer/core/ai.py:33
human_in_loop
View on GitHub →
AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_to_dict, ) from langchain_anthropic import ChatAnt
gpt_engineer/core/ai.py:44
human_in_loop
View on GitHub →
= Union[AIMessage, HumanMessage, SystemMessage] # Set up logging logger = logging.getLogger(__name__) class AI: """ A class that
gpt_engineer/core/ai.py:141
human_in_loop
View on GitHub →
ystem), HumanMessage(content=user), ] return self.next(messages, step_name=step_name) def _extract_content(
gpt_engineer/core/ai.py:233
human_in_loop
View on GitHub →
messages.append(HumanMessage(content=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".
gpt_engineer/core/ai.py:284
human_in_loop
View on GitHub →
e(content="Hello"), HumanMessage(content="How's the weather?")] >>> response = backoff_inference(messages) """ retur

…and 1 more.

Suggested fix · we looked for these and found none

  • decisions_are_addressable
ABSENT
Mechanisms to supersede or deactivate AI systems NIST AI RMF, Art MANAGE 2.3
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • kill_switch_present
  • feature_flag_for_disable
STRONG
Automated individual decision-making, including profiling GDPR, Art 22
2/2 rules

4/4

Why we flagged it

Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%
Evidence · 12 hits— click to view code
gpt_engineer/core/ai.py:33
human_review_path_present
View on GitHub →
AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_to_dict, ) from langchain_anthropic import ChatAnt
gpt_engineer/core/ai.py:44
human_review_path_present
View on GitHub →
= Union[AIMessage, HumanMessage, SystemMessage] # Set up logging logger = logging.getLogger(__name__) class AI: """ A class that
gpt_engineer/core/ai.py:141
human_review_path_present
View on GitHub →
ystem), HumanMessage(content=user), ] return self.next(messages, step_name=step_name) def _extract_content(
gpt_engineer/core/ai.py:233
human_review_path_present
View on GitHub →
messages.append(HumanMessage(content=prompt)) logger.debug( "Creating a new chat completion: %s", "\n".
gpt_engineer/core/ai.py:284
human_review_path_present
View on GitHub →
e(content="Hello"), HumanMessage(content="How's the weather?")] >>> response = backoff_inference(messages) """ retur

…and 7 more.

Fairness

Treat people fairly
3.2/4Adequate5 clauses
STRONG
Exploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_protected_attribute_targeting
STRONG
Social scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_scoring_with_persistent_user_state
STRONG
Predictive policing solely from profiling EU AI Act, Art 5(1)(d)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_crime_risk_scoring_from_profile
STRONG
Biometric categorisation by protected attributes EU AI Act, Art 5(1)(g)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_biometric_categorisation_by_protected_attrs
ABSENT
Fairness and bias evaluated NIST AI RMF, Art MEASURE 2.11
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • bias_evaluation_present

Security & Governance

Don't destabilize society
1.0/4Inadequate4 clauses
ABSENT
Cybersecurity measures appropriate to circumstances EU AI Act, Art 15(5)
1/4 rules

0/4

Why we flagged it

Composite raw score 0.12 (1/4 rules matched).

Confidence
82%
Evidence · 3 hits— click to view code
gpt_engineer/core/ai.py:253
rate_limit_usage
View on GitHub →
ackoff.expo, openai.RateLimitError, max_tries=7, max_time=45) def backoff_inference(self, messages): """ Perform inferen
gpt_engineer/core/ai.py:278
rate_limit_usage
View on GitHub →
openai.error.RateLimitError If the number of retries exceeds the maximum or if the rate limit persists beyond the
gpt_engineer/core/ai.py:280
rate_limit_usage
View on GitHub →
ultimately raise a RateLimitError. Example ------- >>> messages = [SystemMessage(content="Hello"), HumanMessage(co

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • secrets_not_in_prompts
  • adversarial_eval_present
ABSENT
Security and resilience evaluated NIST AI RMF, Art MEASURE 2.7
1/3 rules

0/4

Why we flagged it

Composite raw score 0.12 (1/3 rules matched).

Confidence
77%
Evidence · 3 hits— click to view code
gpt_engineer/core/ai.py:253
rate_limit_usage
View on GitHub →
ackoff.expo, openai.RateLimitError, max_tries=7, max_time=45) def backoff_inference(self, messages): """ Perform inferen
gpt_engineer/core/ai.py:278
rate_limit_usage
View on GitHub →
openai.error.RateLimitError If the number of retries exceeds the maximum or if the rate limit persists beyond the
gpt_engineer/core/ai.py:280
rate_limit_usage
View on GitHub →
ultimately raise a RateLimitError. Example ------- >>> messages = [SystemMessage(content="Hello"), HumanMessage(co

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • adversarial_eval_present
PARTIAL
Security of processing GDPR, Art 32
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 4 hits— click to view code
gpt_engineer/applications/cli/collect.py:56
encryption_at_rest_or_transit
View on GitHub →
https://gptengineerezm.dataplane.rudderstack.com
gpt_engineer/applications/cli/main.py:320
encryption_at_rest_or_transit
View on GitHub →
https://xx.openai.azure.com).
gpt_engineer/core/project_config.py:28
encryption_at_rest_or_transit
View on GitHub →
https://api.gptengineer.app/openapi.json
gpt_engineer/core/token_usage.py:15
encryption_at_rest_or_transit
View on GitHub →
https://github.com/langchain-ai/langchain/blob/535db72607c4ae308566ede4af65295967bb33a8/libs/community/langchain_community/callbacks/openai_info.py

Suggested fix · we looked for these and found none

  • access_control_enforcement
PARTIAL
Resources for AI systems ISO/IEC 42001, Art A.7
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
poetry.lock
dependency_pinning
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_security_policy