SShortSingh.
Back to feed

LangGraph subagents can bypass parent tool limits; middleware fix demonstrated

0
·1 views

A developer testing LangChain 1.3.15 and Deep Agents 0.7.6 found that subagents do not inherit their parent agent's tool restrictions — each subagent receives a fresh, independent permissions grant. In the test, a supervisor agent holding only a write_brief tool spawned a writer subagent that successfully executed an unauthorized web search query, with no system check enforcing the parent's limits. LangChain's own documentation acknowledges this behavior, stating that a subagent spec replaces the parent's rules entirely rather than inheriting them. A GitHub issue (#33879) requesting subagent middleware was filed in November 2025 and remains unresolved, with one pull request closed unmerged and another still in draft. The developer demonstrated a working fix using a custom AgentMiddleware class that intercepts tool calls and blocks any tool not held by the parent agent, effectively enforcing least-privilege inheritance at the subagent level.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer finds 3 security flaws in own AI agent app using Google Antigravity

A developer building GeoMart, an AI-powered survey equipment storefront, for OpenAI's WebMCP Challenge discovered three security vulnerabilities after asking Google Antigravity to audit the full source code. The tool identified an unescaped innerHTML injection flaw and an unprotected API endpoint that allowed quote submissions without any human involvement. An initial fix using an Origin header check proved insufficient, as a Node.js script could simply spoof the header since the expected value was visible in the open-source repository. A more robust solution was implemented using Cloudflare Turnstile, verified server-side against a secret never stored in the codebase, which successfully blocked all replay attacks. The audit also uncovered an unrelated but critical bug: a database migration for storing submitted quotes had never been run, meaning the core human-approval feature had been silently broken throughout development.

0
ProgrammingDEV Community ·

How AI Chat Tools Quietly Replaced Google and Stack Overflow for Developers

Over roughly six years, developers' go-to resource for debugging shifted from Google searches and Stack Overflow threads to AI chat tools like ChatGPT. The author traces the turning point to late 2022, when ChatGPT began answering error messages with context-aware precision, making traditional search feel redundant. Stack Overflow's monthly question volume reportedly fell from over 200,000 to under 50,000 by late 2025, the lowest figure since the platform's early days in 2009. While AI tools offer faster answers, the author argues that the slow, frustrating process of sifting through wrong answers was itself a key learning mechanism. A broader concern is also raised: bugs solved in private AI chat windows leave no public record, quietly eroding the shared knowledge base that the developer community once built together.

0
ProgrammingDEV Community ·

Developer rewrites 14 web scrapers after AI agent silently returned wrong results

A developer discovered that connecting his 14 Apify web-scraping Actors to Claude via the Model Context Protocol (MCP) exposed a critical design flaw in late July 2025. While the scrapers worked perfectly when operated manually, AI agents calling them would receive empty datasets or silently incorrect results because the input schemas assumed human context, such as having the target website open nearby. Unlike human users who can troubleshoot and retry, an AI agent has a single shot to interpret inputs, execute a run, and branch on the output, meaning ambiguous results led it confidently down the wrong path. The most costly example involved a software registry Actor that required an internal opaque integer ID only obtainable by inspecting the site's markup, causing agents passing readable class codes to get clean but empty — or worse, plausibly wrong — results. The developer subsequently refactored all 14 Actors to resolve site-specific lookups internally in code, ensuring any caller without prior site knowledge could still produce correct, distinguishable outcomes.

LangGraph subagents can bypass parent tool limits; middleware fix demonstrated · ShortSingh